216.73.216.197

Kentico Xperience Staging Service Authentication Bypass Vulnerabilities (CVE-2025-2746 & CVE-2025-2747)

· Published 26/03/2025 20:15 · Modified 26/03/2025 20:50

Export JSON

Essential information

Published
26/03/2025 20:15
Modified
26/03/2025 20:50
Tags
2025-03-26 CVE-2025-2746 CVE-2025-2747 CVE-2025-2749 authentication bypass kentico xperience remote code execution
Related entities
3 vulnerabilities (cve), 10 techniques (mitre)

Description

Two critical security flaws, and , have been discovered in 13, a digital experience platform. These vulnerabilities allow unauthenticated attackers to bypass the Staging Sync Server's authentication, potentially gaining administrative control over the CMS. Both issues have a CVSS score of 9.8, indicating their severity. The vulnerabilities affect through version 13.0.178 when the Staging Service is enabled and configured to use username/password authentication. Exploitation can lead to unauthorized administrative access, , data breaches, and system disruption. Mitigation steps include patching, disabling or restricting the Staging Service, using certificate-based authentication, and implementing enhanced monitoring and hardening measures.

External references