Skip to main content
Vulnerability Database/CVE-2026-105046

CVE-2026-105046: Kentico Xperience Auth Bypass Vulnerability

CVE-2026-105046 is an authentication bypass flaw in Kentico Xperience 13 that exposes administration API endpoints without proper authorization checks. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-105046 Overview

CVE-2026-105046 affects Kentico Xperience 13 versions before 13.0.216. The platform lacks object-level authorization checks on administration API endpoints. Authenticated users with low privileges can access or manipulate objects they should not be permitted to interact with. The weakness is classified under [CWE-425] Direct Request (Forced Browsing).

The flaw requires network access and valid low-privilege credentials but no user interaction. Impact is limited to confidentiality disclosure of administrative objects, with no direct integrity or availability impact per the published CVSS vector.

Critical Impact

Authenticated low-privilege users can enumerate or read administrative objects via API endpoints that do not validate per-object authorization, exposing data intended for higher-privileged roles.

Affected Products

  • Kentico Xperience 13 versions prior to 13.0.216
  • Administration API endpoints exposed by the Kentico Xperience platform
  • Deployments relying on role-based access control without object-level enforcement

Discovery Timeline

  • 2026-10-02 - CVE-2026-105046 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-105046

Vulnerability Analysis

The vulnerability resides in Kentico Xperience 13 administration API endpoints. These endpoints enforce authentication but omit object-level authorization checks. An authenticated user can request objects owned by, or scoped to, other users and roles without triggering an access denial.

This class of flaw is commonly referred to as Broken Object Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR). The attacker does not need to bypass authentication. They need only a valid account and the ability to craft API requests that reference arbitrary object identifiers.

Exploitation yields disclosure of information controlled by administration APIs. The CVSS vector reports confidentiality impact only, with no modification or disruption of the affected objects.

Root Cause

The root cause is missing enforcement logic between the authentication layer and the data-access layer. The API confirms the caller is logged in but does not verify that the caller is authorized to interact with the specific object identifier supplied in the request. CWE-425 captures this pattern where resources are returned on direct request without proper validation.

Attack Vector

An attacker with valid low-privilege credentials sends crafted HTTP requests to Kentico Xperience administration API endpoints. By substituting object identifiers in the request path or body, the attacker retrieves objects outside their intended scope. No user interaction is required and the attack is performed over the network.

See the Kentico Platform Overview for product context and the Kentico Hotfixes Download for the fixed release.

Detection Methods for CVE-2026-105046

Indicators of Compromise

  • Authenticated API requests from low-privilege accounts targeting administration endpoints at unusually high volume
  • Sequential or enumerated object identifiers in API request logs indicating resource enumeration
  • Access to objects or sections of the Kentico administration surface not previously used by the account

Detection Strategies

  • Review Kentico application and web server logs for requests to administration API routes made by non-administrator accounts
  • Baseline normal API access patterns per role and alert on deviations such as cross-tenant or cross-user object access
  • Correlate authentication events with subsequent API object access to identify forced-browsing patterns

Monitoring Recommendations

  • Forward Kentico Xperience and IIS logs to a centralized analytics platform for retention and correlation
  • Enable alerting on HTTP 200 responses to administration API endpoints from accounts not assigned administrative roles
  • Track changes to API endpoint access frequency after applying the hotfix to confirm expected behavior

How to Mitigate CVE-2026-105046

Immediate Actions Required

  • Upgrade Kentico Xperience 13 to version 13.0.216 or later using the official hotfix channel
  • Audit administration accounts and remove unnecessary low-privilege access to the administration interface
  • Review recent administration API logs for evidence of unauthorized object access prior to patching

Patch Information

Kentico addressed CVE-2026-105046 in Kentico Xperience 13 version 13.0.216. Download the fix from the Kentico Hotfixes Download page and apply it per the vendor's documented upgrade procedure. Validate the hotfix in a staging environment before deploying to production.

Workarounds

  • Restrict access to the administration interface at the network layer using IP allowlists or VPN gating
  • Reduce the number of accounts with any administration-area access until the hotfix is applied
  • Place a web application firewall rule in front of administration API routes to log and rate-limit requests from non-administrator sessions

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.