← Vulnerability feed

Vulnerability record · CVE-2024-46938 · published 15 September 2024

CVE-2024-46938: Sitecore XP/XM/XC unauthenticated arbitrary file read

SSitecore · Experience Commerce

Sitecore Experience Platform, Experience Manager and Experience Commerce versions 8.0 Initial Release through 10.4 Initial Release contain an information exposure flaw that lets an unauthenticated attacker read arbitrary files. Because the affected products are internet-facing content and commerce platforms, exposed file contents can include configuration and credential material. The record gives no root-cause detail beyond the CWE-200 classification.

7.5 CVSS 3.1 High EPSS 47% · top 1.2% CWE-200 · Information exposure
7.5CVSS 3.1 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file read on internet-facing platforms with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.

What it is

Sitecore Experience Platform, Experience Manager and Experience Commerce versions 8.0 Initial Release through 10.4 Initial Release contain an information exposure flaw that lets an unauthenticated attacker read arbitrary files. Because the affected products are internet-facing content and commerce platforms, exposed file contents can include configuration and credential material. The record gives no root-cause detail beyond the CWE-200 classification.

Impact

An attacker gains read access to files on the server, which can expose configuration files, connection strings, secrets and other sensitive data useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed Sitecore instance in the stated version range is a candidate target.

Exploitation

Not listed in CISA KEV and no public exploit reference is included, but EPSS is 0.46767 (98.77th percentile), indicating a high predicted likelihood of exploitation activity. The only reference is the vendor advisory.

What to do

  • Apply the fix from Sitecore support article KB1003408 for the affected XP/XM/XC versions.
  • If immediate patching is not possible, restrict network access to the Sitecore instance to trusted sources and remove direct internet exposure.
  • Rotate any secrets, connection strings or credentials that may reside in files readable by the application.
  • Review server and application logs for unexpected file-read requests and block offending source addresses.
  • Confirm the deployed Sitecore version and inventory all internet-facing instances in the 8.0 through 10.4 Initial Release range.

Detection

  • Monitor web requests for path traversal or file-path patterns targeting Sitecore endpoints and alert on anomalous file access.
  • Baseline normal file-read behavior and alert on reads of configuration, credential or system files by the web process.
  • Correlate outbound connections or subsequent authentication attempts from the Sitecore host that could indicate use of exfiltrated secrets.
  • Track vendor advisory KB1003408 and re-scan exposed instances for the affected version range.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-46938 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42237Sitecore XP insecure deserialization enables unauthenticated remote code executionSitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No auth…KEVEPSS 98%analysed9.8CVE-2019-9874Sitecore CMS/XP AntiCSRF module .NET deserialization RCEThe Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRF…KEVEPSS 84%analysed9.0CVE-2025-53690Sitecore XM/XP untrusted deserialization enables code injectionSitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. …KEVEPSS 51%analysed9.8CVE-2025-53693Sitecore experience commerce vulnerabilityUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…EPSS 15%9.8CVE-2023-35813Sitecore Experience products remote code execution via code injectionMultiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code inje…EPSS 87%analysed9.8CVE-2023-27068Sitecore experience platform deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…EPSS 1.7%8.8CVE-2025-53691Sitecore experience commerce deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…EPSS 1.6%8.8CVE-2025-34510Sitecore experience commerce relative path traversal vulnerabilitySitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2024-46938), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.