Impact
Kentico Xperience 13 versions prior to 13.0.216 contain a missing object‑level authorization check for administration API endpoints, allowing an authenticated user to access or manipulate resources that should be restricted. This flaw enables an attacker who can authenticate to the administrative interface to read or modify data, disrupt services, or alter system configuration, thereby compromising confidentiality, integrity, and availability. The weakness corresponds to CWE‑425, which highlights absence of authorization checks on data operations.
Affected Systems
Kentico Xperience 13 deployments with a version earlier than 13.0.216 are affected. This includes all installations that have not applied the 13.0.216 release or subsequent patches. Identifiers show the product qualifier “Xperience”, but the specific affected release numbers are the only version information currently available from the CNA.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the moderate severity range. The EPSS score is not provided, so the current likelihood of exploitation is unknown. It is not listed in CISA’s KEV catalog. Attackers would need to be authenticated against the Kentico administration UI and then exploit the lack of object‑level checks to reach restricted data or functionalities. Since there is no network‑exposed remote vector stated, the vector is inferred to be an authenticated session, typical for administrative API misuse.
OpenCVE Enrichment