CVE-2025-2749

9.5 CISA KEV

Kentico · Kentico Xperience

A path traversal and arbitrary file upload vulnerability in Kentico Xperience allows authenticated users to achieve remote code execution via the Staging Sync Server.

Executive summary

A critical path traversal vulnerability in Kentico Xperience is currently being exploited in the wild, enabling attackers to achieve remote code execution.

Vulnerability

The flaw resides in the Staging Sync Server component, where authenticated users can upload arbitrary files to restricted locations. This path traversal leads to remote code execution when malicious content is processed by the server.

Business impact

With a CVSS score of 9.5, this vulnerability represents a severe threat to the confidentiality, integrity, and availability of the Kentico CMS platform. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the web application, leading to full system compromise and potential data exfiltration.

Remediation

Immediate Action: Update Kentico Xperience to version 13.0.178 or later to apply the necessary security fixes.

Proactive Monitoring: Inspect the web server file system for unexpected files or changes in directory structures, particularly within the staging synchronization paths.

Compensating Controls: If immediate patching is not feasible, disable the Staging Sync Server service or switch to X.509-based authentication if it is currently using username and password authentication.

Exploitation status

Public Exploit Available: Yes (published PoC exists via WatchTowr Labs research).

Analyst recommendation

This vulnerability poses a significant risk to enterprise environments using Kentico Xperience. Administrators must prioritize updating the software immediately. Organizations should also audit their configurations to ensure the Staging Sync service is properly secured or disabled if not required for business operations.

More Kentico CVEs

Sources

Originally found and disclosed by Piotr Bazydlo (watchTowr), per the CVE Program record.