Junglewise Threat Intelligence

CVE-2025-2747: Kentico Xperience CMS authentication bypass in Staging Sync Server

CVE-2025-2747 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-10-20

Technologies: Kentico Xperience. Vendors: Kentico.

Executive brief

Kentico Xperience is a content management system (CMS) used to build and manage websites and digital marketing campaigns. A critical security flaw in its staging synchronization component allows unauthorized individuals to bypass login requirements and gain administrative control over the system. This could lead to the theft of sensitive customer data, website defacement, or a total shutdown of the digital platform.

Technical details

An authentication bypass vulnerability (CWE-288) exists in Kentico Xperience through version 13.0.178. The flaw is located within the Staging Sync Server component's handling of passwords when the server is configured with the 'None' password type. A remote, unauthenticated attacker can exploit this over the network to bypass authentication mechanisms and gain control over administrative objects. This vulnerability has been observed being exploited in the wild and can be used as part of a chain to achieve remote code execution (RCE). Hotfixes are available from the vendor's developer portal.

Affected products

  • Kentico Xperience up to and including 13.0.178

Timeline

  • 2025-03-24: disclosed: Initial NVD publication
  • 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-10-20: advisory: CISA advisory published

Related threats