CVE-2025-2746

9.5 CISA KEV

Kentico · Xperience CMS

Kentico Xperience CMS contains an authentication bypass vulnerability in the Staging Sync Server, allowing unauthenticated attackers to gain administrative control through crafted digest authentication.

Executive summary

A critical authentication bypass vulnerability in Kentico Xperience CMS is currently being actively exploited in the wild, posing a severe risk of unauthorized administrative access.

Vulnerability

This flaw involves an authentication bypass within the Staging Sync Server component. It occurs when the service is configured with username and password authentication, allowing an unauthenticated attacker to manipulate digest authentication handling to bypass security checks.

Business impact

Successful exploitation of this vulnerability grants an attacker full administrative control over the CMS, potentially leading to unauthorized data modification, total system compromise, and the execution of further malicious payloads. Given the critical CVSS score of 9.5 and confirmed exploitation in the wild, this vulnerability represents an immediate and extreme risk to organizational security and data integrity.

Remediation

Immediate Action: Update Kentico Xperience 13 to Hotfix 178 immediately to apply the vendor-provided patch.

Proactive Monitoring: Review web server logs for anomalous POST requests directed at the /CMSPages/Staging/SyncServer.asmx endpoint, particularly those containing unusual XML structures or unexpected authentication headers.

Compensating Controls: If immediate patching is not feasible, disable the Staging (Sync) Service if it is not required for business operations, or switch the authentication method to X.509-based authentication, which is not affected by this vulnerability.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept repository is available via the watchTowr Labs GitHub.

Analyst recommendation

Due to the active exploitation of this vulnerability and its critical impact on system security, organizations must prioritize patching as the primary defense. Administrators should verify their current hotfix level immediately and apply Hotfix 178 to all vulnerable instances to mitigate the risk of unauthorized access.

More Kentico CVEs

Sources

Originally found and disclosed by Piotr Bazydlo (watchTowr), per the CVE Program record.