CVE-2025-2747
KEV PoC largeAuthentication Bypass in Kentico Xperience CMS Staging Sync Server
CISA: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2025-2747 is a critical (CVSS 9.8) authentication bypass (CWE-288) in Kentico Xperience CMS, caused by flawed password handling in the Staging Sync Server component for servers configured with the "None" authentication type, affecting versions through 13.0.178. An unauthenticated remote attacker who can reach the Staging Sync Server endpoint can bypass authentication and take control of administrative objects; public research (WatchTowr Labs) shows the flaw can be chained into a pre-authentication remote code execution chain. No privileges or user interaction are required, so any internet-reachable instance of the sync service is directly exposed. All Kentico Xperience deployments running version 13.0.178 or earlier that have the Staging Sync Server enabled are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20, indicating active in-the-wild exploitation, and EPSS assigns a 92.5% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade Kentico Xperience to a release newer than 13.0.178 (apply the latest vendor-patched 13.0 refresh) and verify in the staging configuration that no server entries are defined with the "None" authentication type, which triggers the bypass. If patching is delayed, restrict network access to the Staging Sync Server endpoint (e.g., firewall it to trusted staging peers only) and review access logs for unauthenticated requests to the sync service. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance per the KEV listing by the required due date.
| Kentico Xperience (Xperience CMS) - Staging Sync Server component | through 13.0.178 (all versions up to and including 13.0.178) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
- Affected
- Kentico Xperience CMS
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- kentico
- Products
- xperience
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H