CVE-2019-10068 Details
Description
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10068 | CISA-ADP | US Government Resource |
| http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://devnet.kentico.com/download/hotfixes#securityBugs-v12 | CVE | Release NotesVendor Advisory |
| http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://devnet.kentico.com/download/hotfixes#securityBugs-v12 | [email protected] | Release NotesVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Kentico Xperience Deserialization of Untrusted Data Vulnerability | Mar 25, 2022 | Apr 15, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| kentico xperience | >= 9.0.0, <= 9.0.51 >= 10.0.0, < 10.0.52 >= 11.0.0, < 11.0.48 >= 12.0.0, < 12.0.15 |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 19, 2025 | CPE Deprecation Remap | [email protected] |
| Dec 19, 2025 | CPE Deprecation Remap | [email protected] |
| Dec 19, 2025 | CPE Deprecation Remap | [email protected] |
| Dec 19, 2025 | CPE Deprecation Remap | [email protected] |
| Nov 6, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 14, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 16, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| May 6, 2020 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Apr 1, 2019 | Initial Analysis | [email protected] |