Kentico Xperience Information Disclosure Vulnerability in Authentication Process

Vulnerability

A vulnerability allowing information disclosure has been identified in Kentico Xperience versions through 13.0.159. This vulnerability allows public users to access sensitive hostname details related to the administration interface during the authentication process. Attackers can exploit this issue to retrieve confidential hostname configuration information through a public endpoint, potentially revealing internal network details.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system information, specifically administration interface hostname details, which could include internal network information.

Remediation

Users can upgrade to Kentico Xperience version 13.0.160 or later, where this vulnerability has been addressed. Instructions for applying the hotfix are available on the Kentico Xperience DevNet hotfixes page.

Added: Dec 18, 2025, 8:20 PM
Updated: Dec 18, 2025, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
7.6
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.