CVE-2026-105046: Medium severity Kentico Xperience 13 vulnerability
Published Oct 2, 2026
·Updated
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
Affected Software
1 affected component
Kentico Xperience 13<13.0.216
Event History
Oct 2, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Kentico Xperience 13 deployments running a version before 13.0.216 are affected. The issue concerns administration API endpoints.
2
What access does an attacker need to exploit this issue?
The attacker needs network access and low-privileged authenticated access. No user interaction is required, and exploitation has low complexity.
3
What is the likely impact of successful exploitation?
Successful exploitation can expose limited confidential information. The supplied metrics indicate no integrity or availability impact.
4
How can I remediate the issue?
Update Kentico Xperience 13 to version 13.0.216 or later. The referenced Kentico hotfix download page is the available remediation source in the provided information.