Description
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
Published: 2026-10-02
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Patch Update
AI Analysis

Impact

Kentico Xperience 13 versions prior to 13.0.216 contain a missing object‑level authorization check for administration API endpoints, allowing an authenticated user to access or manipulate resources that should be restricted. This flaw enables an attacker who can authenticate to the administrative interface to read or modify data, disrupt services, or alter system configuration, thereby compromising confidentiality, integrity, and availability. The weakness corresponds to CWE‑425, which highlights absence of authorization checks on data operations.

Affected Systems

Kentico Xperience 13 deployments with a version earlier than 13.0.216 are affected. This includes all installations that have not applied the 13.0.216 release or subsequent patches. Identifiers show the product qualifier “Xperience”, but the specific affected release numbers are the only version information currently available from the CNA.

Risk and Exploitability

The CVSS score of 4.3 places this issue in the moderate severity range. The EPSS score is not provided, so the current likelihood of exploitation is unknown. It is not listed in CISA’s KEV catalog. Attackers would need to be authenticated against the Kentico administration UI and then exploit the lack of object‑level checks to reach restricted data or functionalities. Since there is no network‑exposed remote vector stated, the vector is inferred to be an authenticated session, typical for administrative API misuse.

Generated by OpenCVE AI on October 2, 2026 at 23:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kentico Xperience to version 13.0.216 or later, which adds the missing object‑level authorization checks.
  • If immediate upgrade is not feasible, restrict external network access to all administration API endpoints so that only trusted administrators can reach them, and enforce network segmentation to limit exposure.
  • Monitor API traffic and audit logs for suspicious or unauthorized calls, and apply any hotfixes available from Kentico hotfix repositories to add the missing checks if the upgrade cannot be performed immediately.

Generated by OpenCVE AI on October 2, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Absent Object‑Level Authorization in Kentico Xperience Administration APIs

Fri, 02 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
First Time appeared Kentico
Kentico xperience
Weaknesses CWE-425
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Vendors & Products Kentico
Kentico xperience
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Kentico Xperience
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T21:51:34.920Z

Reserved: 2026-10-02T21:51:34.086Z

Link: CVE-2026-105046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T22:16:54.373

Modified: 2026-10-02T22:16:54.373

Link: CVE-2026-105046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:00:14Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')