← Vulnerability feed

Vulnerability record · CVE-2025-34509 · published 17 June 2025

CVE-2025-34509: Sitecore XM/XP hardcoded account exposes admin API

SSitecore · Experience Commerce

Sitecore Experience Manager and Experience Platform ship with a hardcoded user account across the listed 10.1 through 10.4.1 builds. Because the credential is static and reachable over HTTP, anyone who knows it can authenticate to the administrative API without prior access. The flaw matters because it turns a public-facing CMS into an unauthenticated administrative entry point.

7.5 CVSS 3.1 High EPSS 56% · top 1.0% CWE-798 · Hard-coded credentials
7.5CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote access to an administrative API with a 7.5 CVSS score and very high EPSS, though no KEV listing or confirmed ransomware use.

What it is

Sitecore Experience Manager and Experience Platform ship with a hardcoded user account across the listed 10.1 through 10.4.1 builds. Because the credential is static and reachable over HTTP, anyone who knows it can authenticate to the administrative API without prior access. The flaw matters because it turns a public-facing CMS into an unauthenticated administrative entry point.

Impact

An attacker gains authenticated access to Sitecore's administrative API, which the CVSS vector scores as high confidentiality impact. The record does not state whether that access extends to code execution or data modification, so those outcomes should not be assumed.

Attack surface

Reachable remotely over HTTP with no authentication and no user interaction, per the CVSS vector AV:N/PR:N/UI:N. The hardcoded account is used directly against the administrative API, so no phishing or local foothold is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.55874 (99th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Apply the Sitecore vendor advisory KB1003667 fixes for the affected 10.1, 10.2, 10.3 and 10.4 builds.
  • If patching cannot be immediate, block external access to the administrative API and restrict it to trusted management networks.
  • Rotate or disable the hardcoded account and audit for any authentication events tied to it.
  • Review Sitecore logs and API access records for administrative calls from unexpected source addresses.

Detection

  • Alert on successful authentication to the Sitecore administrative API from external or non-management IP ranges.
  • Search Sitecore and web server logs for the hardcoded account name or its default credential use.
  • Baseline normal administrative API callers and flag new or anomalous clients, especially unauthenticated-then-authenticated sequences.
  • Monitor for administrative API requests originating from hosts that never previously accessed the application.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34509 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42237Sitecore XP insecure deserialization enables unauthenticated remote code executionSitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No auth…KEVEPSS 98%analysed9.8CVE-2019-9874Sitecore CMS/XP AntiCSRF module .NET deserialization RCEThe Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRF…KEVEPSS 84%analysed9.0CVE-2025-53690Sitecore XM/XP untrusted deserialization enables code injectionSitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. …KEVEPSS 51%analysed9.8CVE-2025-53693Sitecore experience commerce vulnerabilityUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…EPSS 15%9.8CVE-2023-35813Sitecore Experience products remote code execution via code injectionMultiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code inje…EPSS 87%analysed9.8CVE-2023-27068Sitecore experience platform deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…EPSS 1.7%8.8CVE-2025-53691Sitecore experience commerce deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…EPSS 1.6%8.8CVE-2025-34510Sitecore experience commerce relative path traversal vulnerabilitySitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2025-34509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.