ZeroHour

CVE-2025-2746

KEV PoC large

Authentication Bypass in Kentico Xperience CMS Staging Sync Server

CISA: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVSS 3.1
9.8 critical
EPSS
59%p99
Published
()
KEV added
AI analysis

Kentico Xperience CMS versions through 13.0.172 contain a critical (CVSS 9.8) authentication bypass (CWE-288) in the Staging Sync Server component, caused by flawed password handling when digest authentication receives an empty SHA1 username. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted digest authentication requests to the staging sync endpoint, with no user interaction required. Successful exploitation lets the attacker bypass authentication and gain control of administrative objects; public research (WatchTowr) shows the bug is part of a pre-auth remote code execution chain. Any Kentico Xperience deployment at or below version 13.0.172 is affected, with highest risk where the Staging Sync Server is enabled and network-reachable. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20, indicating active exploitation, and EPSS puts its 30-day exploitation probability at 59.1% (99th percentile).

What to do: Upgrade Kentico Xperience to a build newer than 13.0.172 per Kentico's security advisory. Until patched, disable the Staging Sync Server or restrict the endpoint to trusted networks only, and rotate staging sync credentials; review logs for unauthenticated staging-sync requests and unexpected changes to administrative objects. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance for cloud services.

Affected
Kentico Xperience CMSthrough 13.0.172
Estimated exposure
largeplausibly tens of thousands of installations, though only those with the Staging Sync Server enabled and exposed are directly reachable — Kentico Xperience 13 is a widely deployed commercial .NET CMS with tens of thousands of installed sites, but this flaw is only reachable on instances running the Staging Sync Server component with the endpoint network-accessible, making…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

CISA Known Exploited Vulnerability
Affected
Kentico Xperience CMS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
kentico
Products
xperience
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news