CVE-2025-2749
Kentico Xperience Path Traversal Vulnerability
Description
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
Description as published by the source, in English.
Key facts
- Published
- 2025-03-24
- Last modified
- 2026-06-17
- Assigned by
- disclosure@vulncheck.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H- Scored by
- disclosure@vulncheck.com
- Probability of exploitation
-
3.9 %
higher than 89 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Yes, see references
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-04-20, with a remediation deadline of 2026-05-04 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Kentico | Xperience | ≤ 13.0.178 | Affected |
Weakness type
-
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special ele…
-
CWE-434: Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1574.010: Services File Permissions Weakness
References
- https://devnet.kentico.com/download/hotfixes
- https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s…
- https://www.vulncheck.com/advisories/kentico-xperience-staging-media-file-upload-authenti…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2749
Related at Berigo
Articles
-
Most compromises still come down to basic security failures
Same product
2026-08-27
CISA has published a review of the vulnerability landscape for fiscal years 2024 and 2025. The headline finding is that most compromises stem from ba…
-
Attackers are logging in to Macs without a password through Screen Sharing
Same product
2026-08-15
Apple shipped an emergency fix for macOS Screen Sharing after a flaw that lets an attacker on the network log in without valid credentials. The Dutch…
-
Records are being pulled from Salesforce and ServiceNow portals that need no login
Same product
2026-08-14
Reco is tracking an ongoing campaign it calls City-Forum, in which a single tool written in Go pulls records from customer portals in Salesforce Expe…
-
Attackers picked up the SharePoint exploit code the day after it was published
Same product
2026-08-14
On 11 August 2026 Rapid7 published a technical analysis of CVE-2026-55040 in Microsoft SharePoint, together with code showing how the flaw is exploit…
Services
-
Security and Preparedness
Operational security capability, CISO-level leadership, ISO 27001 certification and incident preparedness in one pillar. Berigo builds security as a …
-
CISO as a Service
Executive-level security expertise without building an in-house department. Berigo provides senior security leadership on par with group CISOs: flexi…
-
Get Certified: ISO/IEC 27001
A complete ISO/IEC 27001 implementation programme, from current state to a fully certified ISMS. Built for organisations that want real security, not…
-
DPO as a Service
Berigo offers DPO as a Service, an independent data protection officer function that meets the requirements of GDPR Articles 37 to 39, without the ne…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.