Executive brief
Kentico Xperience is a content management system (CMS) used to build and manage websites and digital marketing campaigns. A critical security flaw in its staging synchronization component allows unauthorized individuals to bypass login requirements and gain administrative control over the system. This could lead to the theft of sensitive customer data, website defacement, or a total shutdown of the digital platform.
Technical details
An authentication bypass vulnerability (CWE-288) exists in Kentico Xperience through version 13.0.178. The flaw is located within the Staging Sync Server component's handling of passwords when the server is configured with the 'None' password type. A remote, unauthenticated attacker can exploit this over the network to bypass authentication mechanisms and gain control over administrative objects. This vulnerability has been observed being exploited in the wild and can be used as part of a chain to achieve remote code execution (RCE). Hotfixes are available from the vendor's developer portal.
Affected products
- Kentico Xperience up to and including 13.0.178
Timeline
- 2025-03-24: disclosed: Initial NVD publication
- 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-20: advisory: CISA advisory published