cvedb.io
CVE-2020-36890
HIGH · CVSS 7.2
EPSS exploitation probability: 0%
Published 2025-12-18T20:15:49.347 · Last modified 2026-08-10T18:17:30.063

Summary

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

Affected products

kentico — xperience

Does this affect you?

Add your gear to cvedb and we'll alert you only when kentico ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.