Vulnerability record · CVE-2025-34509 · published 17 June 2025
CVE-2025-34509: Sitecore XM/XP hardcoded account exposes admin API
SSitecore · Experience Commerce
Sitecore Experience Manager and Experience Platform ship with a hardcoded user account across the listed 10.1 through 10.4.1 builds. Because the credential is static and reachable over HTTP, anyone who knows it can authenticate to the administrative API without prior access. The flaw matters because it turns a public-facing CMS into an unauthenticated administrative entry point.
Description
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote access to an administrative API with a 7.5 CVSS score and very high EPSS, though no KEV listing or confirmed ransomware use.
What it is
Sitecore Experience Manager and Experience Platform ship with a hardcoded user account across the listed 10.1 through 10.4.1 builds. Because the credential is static and reachable over HTTP, anyone who knows it can authenticate to the administrative API without prior access. The flaw matters because it turns a public-facing CMS into an unauthenticated administrative entry point.
Impact
An attacker gains authenticated access to Sitecore's administrative API, which the CVSS vector scores as high confidentiality impact. The record does not state whether that access extends to code execution or data modification, so those outcomes should not be assumed.
Attack surface
Reachable remotely over HTTP with no authentication and no user interaction, per the CVSS vector AV:N/PR:N/UI:N. The hardcoded account is used directly against the administrative API, so no phishing or local foothold is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.55874 (99th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Apply the Sitecore vendor advisory KB1003667 fixes for the affected 10.1, 10.2, 10.3 and 10.4 builds.
- If patching cannot be immediate, block external access to the administrative API and restrict it to trusted management networks.
- Rotate or disable the hardcoded account and audit for any authentication events tied to it.
- Review Sitecore logs and API access records for administrative calls from unexpected source addresses.
Detection
- Alert on successful authentication to the Sitecore administrative API from external or non-management IP ranges.
- Search Sitecore and web server logs for the hardcoded account name or its default credential use.
- Baseline normal administrative API callers and flag new or anomalous clients, especially unauthenticated-then-authenticated sequences.
- Monitor for administrative API requests originating from hosts that never previously accessed the application.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/ | ExploitThird Party Advisory |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003667 | Vendor Advisory |
Track CVE-2025-34509 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-34509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.