CVE-2020-36890

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege lev...

high 7.2 CVSS 3.1
Published: Dec 18, 2025
Modified: Dec 24, 2025
Vendor: Kentico
Product: Xperience

Description

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

References

Related CVEs