Authentication Bypass in Kentico Xperience CMS < 13.0.173 (CVE has not been assigned yet)
A critical authentication bypass vulnerability has been identified in Kentico Xperience CMS versions prior to 13.0.173. The vulnerability stems from an issue in the staging endpoint /CMSPages/Staging/SyncServer.asmx that allows attackers to forge requests and bypass authorization controls.
This vulnerability can be exploited to gain full control over affected Xperience instances, specifically those with staging enabled and configured to use username and password authentication. Instances using X.509 certificate-based authentication are not affected. The findings are detailed in this post. Kentico has released a hotfix addressing this vulnerability.