CVE-2025-2746: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
Other sources
Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2746?
CVE-2025-2746 is classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-2746?
To fix CVE-2025-2746, update Kentico Xperience to version 13.0.173 or later.
Who is affected by CVE-2025-2746?
CVE-2025-2746 affects all instances of Kentico Xperience prior to version 13.0.173.
What type of vulnerability is CVE-2025-2746?
CVE-2025-2746 is an authentication bypass vulnerability.
What can an attacker do by exploiting CVE-2025-2746?
An attacker exploiting CVE-2025-2746 can control administrative objects within the affected Kentico Xperience instance.