CVE-2025-2746
KEV PoC largeAuthentication Bypass in Kentico Xperience CMS Staging Sync Server
CISA: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico Xperience CMS versions through 13.0.172 contain a critical (CVSS 9.8) authentication bypass (CWE-288) in the Staging Sync Server component, caused by flawed password handling when digest authentication receives an empty SHA1 username. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted digest authentication requests to the staging sync endpoint, with no user interaction required. Successful exploitation lets the attacker bypass authentication and gain control of administrative objects; public research (WatchTowr) shows the bug is part of a pre-auth remote code execution chain. Any Kentico Xperience deployment at or below version 13.0.172 is affected, with highest risk where the Staging Sync Server is enabled and network-reachable. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20, indicating active exploitation, and EPSS puts its 30-day exploitation probability at 59.1% (99th percentile).
What to do: Upgrade Kentico Xperience to a build newer than 13.0.172 per Kentico's security advisory. Until patched, disable the Staging Sync Server or restrict the endpoint to trusted networks only, and rotate staging sync credentials; review logs for unauthenticated staging-sync requests and unexpected changes to administrative objects. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance for cloud services.
| Kentico Xperience CMS | through 13.0.172 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
- Affected
- Kentico Xperience CMS
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- kentico
- Products
- xperience
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H