EUVD-2025-8008
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 20 Oct 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
