CVE-2024-46938
largeUnauthenticated Arbitrary File Read in Sitecore XP, XM, and XC 8.0–10.4
Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) contain an information-disclosure flaw (CWE-200) that lets an unauthenticated remote attacker read arbitrary files from the server. The issue is triggered over the network with no authentication, no user interaction, and low attack complexity, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields high-confidence confidentiality impact — exposure of sensitive files such as application configuration and secrets — with no integrity or availability impact. Any organization running the affected versions, spanning 8.0 Initial Release through 10.4 Initial Release, is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is known, but an EPSS of 46.8% (99th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Apply Sitecore's security patch for your version line, upgrading deployments beyond the affected 10.4 Initial Release baseline; since no specific fixed build is stated in the advisory data, consult the vendor advisory for the exact remediated release per version. Until patched, restrict Sitecore management and content-delivery endpoints to trusted networks and review web/application logs for anomalous file-read requests. Given the high EPSS score, prioritize internet-facing instances and monitor for emerging PoC or in-the-wild exploitation.
| Sitecore Experience Platform (XP) | 8.0 Initial Release through 10.4 Initial Release |
| Sitecore Experience Manager (XM) | 8.0 Initial Release through 10.4 Initial Release |
| Sitecore Experience Commerce (XC) | 8.0 Initial Release through 10.4 Initial Release |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
- Vendors
- sitecore
- Products
- experience commerce, experience manager, experience platform
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.