PT-2026-104450 · Kentico · Kentico Xperience

CVE-2026-105046

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kentico Xperience versions prior to 13.0.216
Description Lack of object-level authorization checks for administration API endpoints allows unauthorized access to objects.
Recommendations Update to version 13.0.216.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105046

Affected Products

Kentico Xperience