{
  "name": "Kentico Xperience Staging Service Authentication Bypass Vulnerabilities (CVE-2025-2746 & CVE-2025-2747)",
  "slug": "kentico-xperience-staging-service-authentication-bypass-vulnerabilities-cve-2025-2746-cve-2025-2747",
  "description": "Two critical security flaws, CVE-2025-2746 and CVE-2025-2747, have been discovered in Kentico Xperience 13, a digital experience platform. These vulnerabilities allow unauthenticated attackers to bypass the Staging Sync Server's authentication, potentially gaining administrative control over the CMS. Both issues have a CVSS score of 9.8, indicating their severity. The vulnerabilities affect Kentico Xperience through version 13.0.178 when the Staging Service is enabled and configured to use username/password authentication. Exploitation can lead to unauthorized administrative access, remote code execution, data breaches, and system disruption. Mitigation steps include patching, disabling or restricting the Staging Service, using certificate-based authentication, and implementing enhanced monitoring and hardening measures.",
  "published": "2025-03-26T19:15:33+00:00",
  "created_at": "2025-03-26T19:15:33+00:00",
  "modified_at": "2025-03-26T19:50:48+00:00",
  "created_at_opencti": "2025-03-26T19:15:33+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2025-03-26",
    "CVE-2025-2746",
    "CVE-2025-2747",
    "CVE-2025-2749",
    "authentication bypass",
    "kentico xperience",
    "remote code execution"
  ],
  "related_entities": {
    "attack_patterns": [
      {
        "id": "ee82762a-2958-4901-aade-341277d9b410",
        "name": "T1078.004"
      },
      {
        "id": "beaa4978-0309-438b-a45e-ec566b643811",
        "name": "T1505.003"
      },
      {
        "id": "195d9773-4de3-4f61-b94d-a2b53cb65608",
        "name": "T1021.001"
      },
      {
        "id": "c9de6d3f-08cf-448d-8b9f-9aeff59fc48f",
        "name": "T1550"
      },
      {
        "id": "19ce62bb-3faf-4d09-90b1-d82fce1ba8b0",
        "name": "T1136"
      },
      {
        "id": "e73b317e-ea92-49b4-a45d-051f7279aced",
        "name": "T1213"
      },
      {
        "id": "6b7df637-ffba-4104-b70e-5bd05637d0f6",
        "name": "T1212"
      },
      {
        "id": "6c8f8a40-2746-4a37-86bd-81e82afa6e62",
        "name": "T1190"
      },
      {
        "id": "b9eab970-53dd-4977-9a26-c4fe566e422d",
        "name": "T1133"
      },
      {
        "id": "9f11a241-9abc-4c57-95dd-33955ab08826",
        "name": "T1078"
      }
    ],
    "vulnerabilities": [
      {
        "id": "",
        "name": "CVE-2025-2749"
      },
      {
        "id": "",
        "name": "CVE-2025-2747"
      },
      {
        "id": "",
        "name": "CVE-2025-2746"
      }
    ]
  },
  "external_refs": [
    "https://securityboulevard.com/2025/03/exploited-kentico-xperience-staging-service-authentication-bypass-vulnerabilities-cve-2025-2746-cve-2025-2747/",
    "https://otx.alienvault.com/pulse/67e46065a414650e2ec93230"
  ]
}