ZeroHour

CVE-2025-2749

KEV PoC large

Path Traversal to Authenticated RCE in Kentico Xperience Through 13.0.178

CISA: Kentico Xperience Path Traversal Vulnerability

CVSS 3.1
7.2 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2025-2749 is a path traversal and unrestricted file upload flaw (CWE-22/CWE-434) in the Staging Sync Server component of Kentico Xperience, exploitable by an authenticated user with staging sync privileges. The user can upload arbitrary data to path-relative locations, escaping the intended upload directory and writing attacker-controlled files — including executable server-side content such as script files — anywhere the application can reach, resulting in remote code execution on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 3.1: 7.2 High, network-accessible with high privileges required). All Kentico Xperience versions through 13.0.178 are affected, primarily deployments where the Staging Sync Server endpoint is reachable by attackers or by accounts with weak or stolen credentials. The flaw is confirmed actively exploited — it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-20 — and a public technical write-up with proof-of-concept details is available from watchTowr Labs.

What to do: Upgrade Kentico Xperience to a hotfix release later than 13.0.178 per the vendor's instructions (federal agencies must follow BOD 22-01 guidance or the KEV-required action by the stated deadline). Until patched, restrict access to the Staging Sync Server endpoint (e.g., via VPN/firewall allowlisting) and review high-privilege staging/sync accounts for suspicious use. Hunt for signs of compromise such as unexpected executable or script files uploaded outside intended directories and webshells in the web root, since the vulnerability is listed in CISA's KEV as actively exploited.

Affected
Kentico Xperienceall versions through 13.0.178 (inclusive)
Estimated exposure
large≈ tens of thousands (10k–100k) of Kentico Xperience deployments, with an unknown but smaller subset exposing the staging sync endpoint to the internet — Kentico Xperience is a widely deployed commercial CMS with a customer base historically reported in the tens of thousands of sites, and public internet scans regularly surface Kentico instances; however, only deployments that enable and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CISA Known Exploited Vulnerability
Affected
Kentico Kentico Xperience
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
kentico
Products
xperience
Weakness
CWE-22, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news