Junglewise Threat Intelligence

CVE-2025-2746: Kentico Xperience authentication bypass in Staging Sync Server

CVE-2025-2746 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-10-20

Technologies: Kentico Xperience. Vendors: Kentico.

Executive brief

Kentico Xperience is a content management system (CMS) used to build and manage websites. A critical security flaw allows unauthorized individuals to bypass login requirements and gain administrative control over the system. This could lead to the theft of sensitive data, website defacement, or a total shutdown of the service. This vulnerability is reportedly being exploited in the wild.

Technical details

An authentication bypass vulnerability (CWE-288) exists in Kentico Xperience through version 13.0.172. The flaw is located within the Staging Sync Server's digest authentication mechanism, specifically in how it handles empty SHA1 usernames. A remote, unauthenticated attacker can exploit this logic error to bypass authentication requirements. Successful exploitation allows the attacker to control administrative objects, potentially leading to full system compromise. Hotfixes are available from the vendor's developer portal.

Affected products

  • Kentico Xperience Up to and including 13.0.172

Timeline

  • 2025-03-24: disclosed: Initial NVD publication date
  • 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-10-20: advisory: CISA advisory published

Related threats