Authorization Flaw in Kentico Xperience by Kentico
CVE-2026-105046

4.3MEDIUM

Key Information:

Vendor

Kentico

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-105046?

Kentico Xperience 13 versions prior to 13.0.216 are prone to a security vulnerability due to the absence of object-level authorization checks in their administration API endpoints. This flaw could potentially allow unauthorized access and manipulation of sensitive administrative data, highlighting the importance of implementing proper authorization controls to safeguard against unauthorized actions.

Affected Version(s)

Xperience 13.0.0 < 13.0.216

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.