Critical authentication bypass vulnerability in Kentico Xperience CMS allows complete bypass of authentication via Staging Sync Server component. The vulnerability gives attackers control over administrative objects and is actively being exploited in the wild according to CISA KEV listing.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-03-24
Added to CISA KEV: 2025-10-20 210 DAYS BETWEEN CVE AND KEV
CVE-2025-2747 is a critical authentication bypass vulnerability affecting Kentico Xperience [2]. Below is the summary of known information regarding this vulnerability:
Critical authentication bypass in Kentico Xperience allows unauthorized access. Apply patches immediately to prevent exploitation. ... CVE-2025-2747 is a critical authentication bypass vulnerability affecting Kentico Xperience through version 13.0.178. Organizations are urged to apply necessary patc…
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling. ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official,…
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million ... https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms. https://www.cisa.gov/known-exploited-vulnerabil…
CISA has added five new vulnerabilities to its KEV Catalog, based on evidence of active exploitation.