CVE-2025-34509
PoC largeHardcoded Account Backdoor in Sitecore XM/XP Allows Unauthenticated Admin API Access
Sitecore Experience Manager (XM) and Experience Platform (XP) ship with a hardcoded user account (CWE-798), publicly reported as using the password 'b', on versions 10.1 through 10.1.4 rev. 011974 PRE, all 10.2 versions, 10.3 through 10.3.3 rev. 011967 PRE, and 10.4 through 10.4.1 rev. 011941 PRE. Because the credentials are embedded in the product, any unauthenticated remote attacker can authenticate over HTTP and reach the administrative API, yielding high-impact access to administrative functions and data (CVSS 7.5, high confidentiality impact). watchTowr Labs has published research showing this account can be chained with other Sitecore flaws, including cache poisoning, to achieve pre-authentication remote code execution, raising the practical risk beyond the direct information-disclosure score. Organizations running affected Sitecore XM/XP releases - including Experience Commerce and Managed Cloud deployments - are exposed, especially where the administrative API is reachable from the internet. The flaw has a public PoC but is not yet on CISA's KEV list, and EPSS assigns a 55.3% probability of exploitation within 30 days (99th percentile), so active exploitation is considered likely.
What to do: Upgrade all XM/XP deployments in the affected ranges to a fixed update (releases newer than 10.4.1 rev. 011941 PRE on each affected line) per Sitecore's advisory; if patching is delayed, restrict HTTP access to the administrative API endpoints from untrusted networks and disable or remove the hardcoded account. Check access logs for use of the 'b' account and for activity matching the watchTowr pre-auth RCE chain (cache poisoning chained with the hardcoded account), and prioritize remediation given the 55.3% EPSS score.
| Sitecore Experience Manager (XM) | 10.1 to 10.1.4 rev. 011974 PRE; all 10.2 versions; 10.3 to 10.3.3 rev. 011967 PRE; 10.4 to 10.4.1 rev. 011941 PRE |
| Sitecore Experience Platform (XP) | 10.1 to 10.1.4 rev. 011974 PRE; all 10.2 versions; 10.3 to 10.3.3 rev. 011967 PRE; 10.4 to 10.4.1 rev. 011941 PRE |
| Sitecore Experience Commerce | Deployments built on the affected XM/XP versions (10.1 to 10.4.1 ranges above) |
| Sitecore Managed Cloud | Hosted XM/XP deployments on the affected 10.1 to 10.4.1 ranges above |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
- Vendors
- sitecore
- Products
- experience commerce, experience manager, experience platform, managed cloud
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N