Junglewise Threat Intelligence

CVE-2025-2749: Kentico Xperience path traversal and RCE in Staging Sync Server

CVE-2025-2749 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2026-04-20

Technologies: Kentico Xperience. Vendors: Kentico.

Executive brief

Kentico Xperience, a digital experience and content management platform, contains a security flaw in its staging synchronization component. An attacker with administrative or staging credentials can upload malicious files to unauthorized locations on the server. This can lead to a complete takeover of the web server, allowing the attacker to steal data, modify website content, or disrupt business operations.

Technical details

A path traversal vulnerability (CWE-22) and unrestricted file upload (CWE-434) exist within the Kentico Xperience Staging Sync Server. The flaw allows an authenticated user to bypass directory restrictions and upload arbitrary data to relative path locations on the server. By uploading executable content (such as web shells) to web-accessible directories, an attacker can achieve remote code execution (RCE). While the vulnerability requires authentication (High privileges), it has been observed being exploited in the wild, potentially as part of an exploit chain. Hotfixes are available from the vendor for affected versions up to 13.0.178.

Affected products

  • Kentico Xperience Up to and including 13.0.178

Timeline

  • 2025-03-24: disclosed: Initial NVD publication date
  • 2025-10-17: patched: Vendor hotfixes identified
  • 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-04-20: exploited: Confirmed active exploitation in the wild

Related threats