Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels. | |
| Title | Kentico Xperience <= 10 Administrator Access Control Bypass | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:48:19.613Z
Reserved: 2025-12-09T11:05:19.896Z
Link: CVE-2020-36890
Updated: 2025-12-18T21:09:13.743Z
Status : Analyzed
Published: 2025-12-18T20:15:49.347
Modified: 2025-12-24T18:15:25.033
Link: CVE-2020-36890
No data.
OpenCVE Enrichment
No data.