CVE-2025-2746
About
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
Rainforest analyst review
Kentico Xperience mishandles digest authentication in its Staging Sync Server: the password handling accepts an empty SHA1 hash for a username, so an attacker supplying crafted digest credentials is authenticated without knowing any real password. That bypass grants control over administrative objects in the CMS, letting an attacker manipulate the platform's content and configuration as a privileged user through the staging interface.
Xperience is an enterprise content-management and digital-experience platform, so the sites it runs are often public-facing corporate and commercial web properties, and administrative control there means the ability to alter published content, plant malicious code for site visitors, or pivot deeper into the hosting environment. The staging endpoint is a natural exposure because it is designed to be reached by other servers for content synchronization. Upgrade beyond the affected 13.0.172 to a fixed build, and restrict the Staging Sync Server interface to the specific trusted hosts that legitimately use it rather than leaving it broadly reachable. Where administrative objects may already have been touched, audit CMS admin accounts and recent content and configuration changes for tampering.
References
- https://devnet.kentico.com/download/hotfixes
- https://github.com/watchtowrlabs/kentico-xperience13-AuthBypass-wt-2025-0011
- https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms/
- https://www.vulncheck.com/advisories/kentico-xperience-staging-sync-server-digest-password-authentication-bypass
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2746
Related CVEs
Frequently asked questions
What is CVE-2025-2746?
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
How severe is CVE-2025-2746?
CVE-2025-2746 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2025-2746 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-2746?
Public advisories list the following as affected: xperience. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-2746?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
