CVE-2019-10068: Kentico Xperience Deserialization of Untrusted Data Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 95.1% chance of exploitation in the next 30 days.

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

Affected products

  • Kentico Xperience: from 9.0.0, up to and including 9.0.51; from 10.0.0, before 10.0.52 (fixed in 10.0.52); from 11.0.0, before 11.0.48 (fixed in 11.0.48); from 12.0.0, before 12.0.15 (fixed in 12.0.15)

Published 2019-03-26. Last modified 2026-06-17.