---
cve: "CVE-2026-7198"
severity: "CRITICAL"
cvss: 9.8
epss: "44%"
vendor: "Progress Software"
kev: false
exploited: false
published: "2026-06-02 14:17:14"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T05:48:48+02:00"
---

# CVE-2026-7198

> 9.8 CRITICAL

## Beschreibung

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-284** — Improper Access Control
  The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

## Angriffsmuster (CAPEC)

- [CAPEC-19 — Embedding Scripts within Scripts](https://capec.mitre.org/data/definitions/19.html) _(Severity: High)_
- [CAPEC-441 — Malicious Logic Insertion](https://capec.mitre.org/data/definitions/441.html) _(Severity: High)_
- [CAPEC-478 — Modification of Windows Service Configuration](https://capec.mitre.org/data/definitions/478.html) _(Severity: High)_
- [CAPEC-479 — Malicious Root Certificate](https://capec.mitre.org/data/definitions/479.html) _(Severity: Low)_
- [CAPEC-502 — Intent Spoof](https://capec.mitre.org/data/definitions/502.html)
- [CAPEC-503 — WebView Exposure](https://capec.mitre.org/data/definitions/503.html)
- [CAPEC-536 — Data Injected During Configuration](https://capec.mitre.org/data/definitions/536.html) _(Severity: High)_
- [CAPEC-546 — Incomplete Data Deletion in a Multi-Tenant Environment](https://capec.mitre.org/data/definitions/546.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1027.009 — Obfuscated Files or Information: Embedded Payloads](https://attack.mitre.org/techniques/T1027/009/)
- [T1546.004 — Event Triggered Execution:.bash_profile and .bashrc](https://attack.mitre.org/techniques/T1546/004/)
- [T1546.016 — Event Triggered Execution: Installer Packages](https://attack.mitre.org/techniques/T1546/016/)
- [T1574.011 — Hijack Execution Flow:Service Registry Permissions Weakness](https://attack.mitre.org/techniques/T1574/011/)
- [T1543.003 — Create or Modify System Process:Windows Service](https://attack.mitre.org/techniques/T1543/003/)
- [T1553.004 — Subvert Trust Controls:Install Root Certificate](https://attack.mitre.org/techniques/T1553/004/)

## Referenzen

- <https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-7198) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
