Vulnerability record · CVE-2024-46938 · published 15 September 2024
CVE-2024-46938: Sitecore XP/XM/XC unauthenticated arbitrary file read
SSitecore · Experience Commerce
Sitecore Experience Platform, Experience Manager and Experience Commerce versions 8.0 Initial Release through 10.4 Initial Release contain an information exposure flaw that lets an unauthenticated attacker read arbitrary files. Because the affected products are internet-facing content and commerce platforms, exposed file contents can include configuration and credential material. The record gives no root-cause detail beyond the CWE-200 classification.
Description
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file read on internet-facing platforms with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.
What it is
Sitecore Experience Platform, Experience Manager and Experience Commerce versions 8.0 Initial Release through 10.4 Initial Release contain an information exposure flaw that lets an unauthenticated attacker read arbitrary files. Because the affected products are internet-facing content and commerce platforms, exposed file contents can include configuration and credential material. The record gives no root-cause detail beyond the CWE-200 classification.
Impact
An attacker gains read access to files on the server, which can expose configuration files, connection strings, secrets and other sensitive data useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed Sitecore instance in the stated version range is a candidate target.
Exploitation
Not listed in CISA KEV and no public exploit reference is included, but EPSS is 0.46767 (98.77th percentile), indicating a high predicted likelihood of exploitation activity. The only reference is the vendor advisory.
What to do
- Apply the fix from Sitecore support article KB1003408 for the affected XP/XM/XC versions.
- If immediate patching is not possible, restrict network access to the Sitecore instance to trusted sources and remove direct internet exposure.
- Rotate any secrets, connection strings or credentials that may reside in files readable by the application.
- Review server and application logs for unexpected file-read requests and block offending source addresses.
- Confirm the deployed Sitecore version and inventory all internet-facing instances in the 8.0 through 10.4 Initial Release range.
Detection
- Monitor web requests for path traversal or file-path patterns targeting Sitecore endpoints and alert on anomalous file access.
- Baseline normal file-read behavior and alert on reads of configuration, credential or system files by the web process.
- Correlate outbound connections or subsequent authentication attempts from the Sitecore host that could indicate use of exfiltrated secrets.
- Track vendor advisory KB1003408 and re-scan exposed instances for the affected version range.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003408 | Vendor Advisory |
Track CVE-2024-46938 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-46938), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.