CVE-2025-2746
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-2746 is a newly identified vulnerability in Kentico Xperience that enables authentication bypass. This issue arises due to the Staging Sync Server's flawed handling of empty SHA1 usernames in digest authentication. The bypass of authentication grants attackers administrative control over the affected system, which includes version 13.0.172 of Xperience. This vulnerability poses a significant risk, as unauthorized access to administrative objects could lead to data breaches, unintended system modifications, or other malicious activities. To mitigate this risk, Kentico Xperience users are strongly encouraged to apply available patches or updates as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft