CVE-2026-105046: Kentico Xperience

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.

Affected products

  • Kentico Xperience: from 13.0.0, before 13.0.216 (fixed in 13.0.216)

Published 2026-10-02. Last modified 2026-10-06.