CVE-2025-2746

CRITICAL KEV NUCLEI

Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2025-2746 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 20, 2025. A Nuclei detection template is also available.

Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

Nuclei Templates (1)

Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
CRITICALVERIFIEDby DhiyaneshDK
FOFA: app="Kentico-CMS"

Scores

CVSS v3 9.8
EPSS 0.9022
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2025-10-20
VulnCheck KEV 2025-10-20
ENISA EUVD EUVD-2025-8008
CWE
CWE-288
Status published
Products (1)
kentico/xperience < 13.0.172
Published Mar 24, 2025
KEV Added Oct 20, 2025
Tracked Since Feb 18, 2026