Description
An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.
Problem types
Product status
Credits
Denis Styopochkin - Security Engineer, SoftServe
References
devnet.kentico.com/download/hotfixes (Kentico DevNet Hotfixes)
www.vulncheck.com/...nce-administrator-access-control-bypass (VulnCheck Advisory: Kentico Xperience <= 10 Administrator Access Control Bypass)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.