CVE-2025-2749
KEV PoC largePath Traversal to Authenticated RCE in Kentico Xperience Through 13.0.178
CISA: Kentico Xperience Path Traversal Vulnerability
CVE-2025-2749 is a path traversal and unrestricted file upload flaw (CWE-22/CWE-434) in the Staging Sync Server component of Kentico Xperience, exploitable by an authenticated user with staging sync privileges. The user can upload arbitrary data to path-relative locations, escaping the intended upload directory and writing attacker-controlled files — including executable server-side content such as script files — anywhere the application can reach, resulting in remote code execution on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 3.1: 7.2 High, network-accessible with high privileges required). All Kentico Xperience versions through 13.0.178 are affected, primarily deployments where the Staging Sync Server endpoint is reachable by attackers or by accounts with weak or stolen credentials. The flaw is confirmed actively exploited — it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-20 — and a public technical write-up with proof-of-concept details is available from watchTowr Labs.
What to do: Upgrade Kentico Xperience to a hotfix release later than 13.0.178 per the vendor's instructions (federal agencies must follow BOD 22-01 guidance or the KEV-required action by the stated deadline). Until patched, restrict access to the Staging Sync Server endpoint (e.g., via VPN/firewall allowlisting) and review high-privilege staging/sync accounts for suspicious use. Hunt for signs of compromise such as unexpected executable or script files uploaded outside intended directories and webshells in the web root, since the vulnerability is listed in CISA's KEV as actively exploited.
| Kentico Xperience | all versions through 13.0.178 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
- Affected
- Kentico Kentico Xperience
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- kentico
- Products
- xperience
- Weakness
- CWE-22, CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H