CVE-2020-36890: Kentico Xperience <= 10 Administrator Access Control Bypass
An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36890?
CVE-2020-36890 has been rated as a critical vulnerability due to its potential to compromise global administrator accounts.
How do I fix CVE-2020-36890?
To fix CVE-2020-36890, ensure that you apply the latest hotfix provided by Kentico for the affected versions of Xperience.
What could an attacker do with CVE-2020-36890?
An attacker exploiting CVE-2020-36890 could alter global administrator user privileges and manipulate security-sensitive macros.
Which versions of Kentico Xperience are affected by CVE-2020-36890?
CVE-2020-36890 affects all versions of Kentico Xperience up to and including version 10.
Is there a workaround for CVE-2020-36890?
There is no officially recommended workaround for CVE-2020-36890, therefore applying the hotfix immediately is advised.