CVE-2025-2746
Description
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
Summary dbcve.org
Kentico Xperience contains an authentication bypass vulnerability in the Staging Sync Server component. The flaw is in how the system handles empty SHA1 usernames during digest authentication processing, allowing unauthenticated attackers to bypass authentication and gain control over administrative objects. This affects all versions through 13.0.172.
Mitigation
Upgrade Kentico Xperience to version 13.0.173 or later to patch the authentication bypass. If immediate patching is not feasible, restrict network-level access to the Staging Sync Server endpoints and implement additional authentication layers such as VPN or IP whitelisting.