Description
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.
Published: 2026-06-02
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote unauthenticated attacker to retrieve plain‑text credentials that are used to connect to the Sitefinity Insight web service. An attacker can obtain these credentials without possessing valid authentication to the application, which can then be leveraged to gain unauthorized access to the Insight service or other components that use the same credentials. This constitutes a serious exposure of authentication data and could be a stepping stone to further compromise of the Sitefinity environment.

Affected Systems

Progress Software’s Sitefinity web content management system is affected in multiple version ranges: 14.0.7700 through 14.4.8152, 15.0.8200 through 15.0.8234, 15.1.8300 through 15.1.8335, 15.2.8400 through 15.2.8441, 15.3.8500 through 15.3.8531, and 15.4.8600 through 15.4.8630. The flaw is present only when the Sitefinity Insight service is actively integrated and the site is not using the default configuration. Missing or later versions are assumed to be patched.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified, but a lack of EPSS data does not imply low risk. The vulnerability is not listed in the CISA KEV catalog, although it remains a critical issue because exploitation requires no credentials and can be performed remotely. The likely attack vector involves sending a crafted request to the Insight service endpoint, exploiting the inadequate protection of the stored credentials. Successful exploitation depends on the presence of the Insight integration and a non‑default configuration, conditions that many deployments satisfy.

Generated by OpenCVE AI on June 2, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sitefinity to a version newer than 15.4.8630, ensuring it falls outside all affected version ranges; this is the official vendor fix.
  • If upgrading is not immediately possible, disable the Sitefinity Insight integration or remove the service entirely from the configuration to eliminate the credential exposure.
  • For environments that must continue using Insight, enforce secure credential handling by restricting the credentials to HTTPS only, changing them frequently, and applying the vendor’s recommended patch for credential protection.

Generated by OpenCVE AI on June 2, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522

Tue, 02 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.
Title CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-06-02T15:11:54.622Z

Reserved: 2026-04-28T12:53:06.945Z

Link: CVE-2026-7312

cve-icon Vulnrichment

Updated: 2026-06-02T15:11:50.455Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-02T14:17:14.470

Modified: 2026-06-02T14:37:13.613

Link: CVE-2026-7312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T16:00:17Z

Weaknesses