Kentico Xperience Access Control Bypass Vulnerability Allowing Privilege Modification

Vulnerability

A vulnerability allowing access control bypass has been identified in Kentico Xperience versions through 12.0.60. This vulnerability enables administrators to alter global administrator user privileges by sending unauthorized requests. As a result, attackers could potentially compromise global administrator accounts and disrupt security-sensitive macros by changing user privilege levels.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of global administrator privileges, allowing attackers to compromise administrator accounts and interfere with security-sensitive macros.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.

Added: Dec 18, 2025, 8:45 PM
Updated: Dec 18, 2025, 8:45 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
5.0
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.