Vulnerability record · CVE-2017-17736 · published 23 March 2018
CVE-2017-17736: Kentico CMS install page access control bypass grants admin
Kentico · Xperience
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 exposes CMSInstall/install.aspx in a way that bypasses access control, letting a remote unauthenticated attacker reach the CMS Administration Dashboard with Global Administrator rights. Because the flaw grants full administrative control of the CMS, it is a complete compromise of the application.
Description
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote access control bypass leading to full Global Administrator control, with high EPSS and public exploit references.
What it is
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 exposes CMSInstall/install.aspx in a way that bypasses access control, letting a remote unauthenticated attacker reach the CMS Administration Dashboard with Global Administrator rights. Because the flaw grants full administrative control of the CMS, it is a complete compromise of the application.
Impact
An attacker gains Global Administrator access to the Kentico CMS, allowing full control over content, configuration, and any data or integrations the CMS manages.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N; the attacker simply requests CMSInstall/install.aspx and then navigates to the administration dashboard.
Exploitation
Not listed in CISA KEV, but EPSS is 0.68457 (99.3rd percentile) and both references are tagged Exploit, indicating public exploit material exists and exploitation is likely.
What to do
- Upgrade Kentico to 9.0.51 or later, or 10.0.48 or later, as the record specifies these fixed versions.
- If immediate upgrade is not possible, block or restrict access to CMSInstall/install.aspx at the web server or WAF.
- Remove or disable the CMSInstall directory on production instances.
- Verify no unauthorized Global Administrator accounts were created and review CMS administrative activity.
- Restrict network access to the CMS administration interface to trusted sources.
Detection
- Monitor web logs for requests to CMSInstall/install.aspx, especially from external or unexpected sources.
- Alert on creation of new Global Administrator accounts or privilege changes in Kentico.
- Review CMS administration dashboard logins from unusual IP addresses or outside normal hours.
- Check for unexpected changes to CMS configuration, content, or installed modules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.hivint.com/advisory-access-control-bypass-in-kentico-cms-cve-2017-17736-49e1e43ae55b | ExploitThird Party Advisory |
| https://blog.hivint.com/advisory-access-control-bypass-in-kentico-cms-cve-2017-17736-49e1e43ae55b | ExploitThird Party Advisory |
Track CVE-2017-17736 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-17736), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.