CVE-2025-34509
Published: Jun 17, 2025
Modified: Feb 26, 2026
CVSS v3.1
7.5
Description
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
| Vendor | Product | Versions |
|---|---|---|
Sitecore | Experience Manager | affected 10.4 - < 10.4.1 rev. 011941 PREaffected 10.3 - < 10.3.3 rev. 011967 PREaffected 10.1 - < 10.1.4 rev. 011974 PRE |
Sitecore | Experience Platform | affected 10.4 - < 10.4.1 rev. 011941 PREaffected 10.3 - < 10.3.3 rev. 011967 PREaffected 10.1 - < 10.1.4 rev. 011974 PRE |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now