Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-02T21:51:34.920Z
Reserved: 2026-10-02T21:51:34.086Z
Link: CVE-2026-105046
No data.
Status : Received
Published: 2026-10-02T22:16:54.373
Modified: 2026-10-02T22:16:54.373
Link: CVE-2026-105046
No data.
OpenCVE Enrichment
No data.
Weaknesses