Executive brief
Kentico Xperience is a content management system (CMS) used to build and manage websites. A critical security flaw allows unauthorized individuals to bypass login requirements and gain administrative control over the system. This could lead to the theft of sensitive data, website defacement, or a total shutdown of the service. This vulnerability is reportedly being exploited in the wild.
Technical details
An authentication bypass vulnerability (CWE-288) exists in Kentico Xperience through version 13.0.172. The flaw is located within the Staging Sync Server's digest authentication mechanism, specifically in how it handles empty SHA1 usernames. A remote, unauthenticated attacker can exploit this logic error to bypass authentication requirements. Successful exploitation allows the attacker to control administrative objects, potentially leading to full system compromise. Hotfixes are available from the vendor's developer portal.
Affected products
- Kentico Xperience Up to and including 13.0.172
Timeline
- 2025-03-24: disclosed: Initial NVD publication date
- 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-20: advisory: CISA advisory published