CVE-2025-2747
Description
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
Summary dbcve.org
Kentico Xperience versions through 13.0.178 contain an authentication bypass vulnerability in the Staging Sync Server component. The vulnerability stems from improper password handling for servers configured with the 'None' type, allowing unauthenticated attackers to bypass authentication and gain control over administrative objects.
Mitigation
Upgrade Kentico Xperience to version 13.0.179 or later. Alternatively, review and reconfigure staging server settings to avoid the 'None' type definition, and ensure staging servers use proper authentication mechanisms.