Vulnerability record · CVE-2023-35813 · published 17 June 2023
CVE-2023-35813: Sitecore Experience products remote code execution via code injection
SSitecore · Experience Commerce
Multiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code injection flaw that permits remote code execution. The vulnerability is network-reachable with no authentication or user interaction required, and the record does not specify the exact injection point or vulnerable component.
Description
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and very high EPSS make this an urgent patch-first vulnerability.
What it is
Multiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code injection flaw that permits remote code execution. The vulnerability is network-reachable with no authentication or user interaction required, and the record does not specify the exact injection point or vulnerable component.
Impact
An unauthenticated attacker can execute arbitrary code on the affected Sitecore server, leading to full compromise of confidentiality, integrity, and availability. This could allow data theft, web shell deployment, or lateral movement into connected systems.
Attack surface
The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is exploitable over the network with no privileges or user interaction. The description does not identify the specific endpoint or interface, so the exact reachable surface is unknown from this record.
Exploitation
CVE-2023-35813 is not listed in CISA KEV and has no documented ransomware use, but EPSS is very high (0.867, 99.7th percentile), indicating a strong likelihood of exploitation activity. The vendor references are tagged Mitigation, Patch, and Vendor Advisory, confirming a fix exists.
What to do
- Apply the vendor patch or mitigation from Sitecore KB1002979 immediately.
- If patching is not possible, restrict network access to Sitecore administrative and public endpoints to trusted sources.
- Monitor Sitecore logs and application behavior for unexpected code execution or file writes.
- Review and harden any custom code or integrations that could be injection vectors.
- Validate that all Sitecore instances are at a supported version and not exposed directly to the internet without a WAF.
Detection
- Hunt for unusual child processes spawned by the Sitecore application pool (w3wp.exe) or Java processes.
- Monitor for unexpected file creation or modification in Sitecore web directories and bin folders.
- Alert on anomalous outbound network connections from Sitecore servers to unknown hosts.
- Review Sitecore audit logs for suspicious administrative actions or requests to unusual endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002979 | MitigationPatchVendor Advisory |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002979 | MitigationPatchVendor Advisory |
Track CVE-2023-35813 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35813), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.