ZeroHour

CVE-2025-34509

PoC large

Hardcoded Account Backdoor in Sitecore XM/XP Allows Unauthenticated Admin API Access

CVSS 3.1
7.5 high
EPSS
55%p99
Published
()
Modified
AI analysis

Sitecore Experience Manager (XM) and Experience Platform (XP) ship with a hardcoded user account (CWE-798), publicly reported as using the password 'b', on versions 10.1 through 10.1.4 rev. 011974 PRE, all 10.2 versions, 10.3 through 10.3.3 rev. 011967 PRE, and 10.4 through 10.4.1 rev. 011941 PRE. Because the credentials are embedded in the product, any unauthenticated remote attacker can authenticate over HTTP and reach the administrative API, yielding high-impact access to administrative functions and data (CVSS 7.5, high confidentiality impact). watchTowr Labs has published research showing this account can be chained with other Sitecore flaws, including cache poisoning, to achieve pre-authentication remote code execution, raising the practical risk beyond the direct information-disclosure score. Organizations running affected Sitecore XM/XP releases - including Experience Commerce and Managed Cloud deployments - are exposed, especially where the administrative API is reachable from the internet. The flaw has a public PoC but is not yet on CISA's KEV list, and EPSS assigns a 55.3% probability of exploitation within 30 days (99th percentile), so active exploitation is considered likely.

What to do: Upgrade all XM/XP deployments in the affected ranges to a fixed update (releases newer than 10.4.1 rev. 011941 PRE on each affected line) per Sitecore's advisory; if patching is delayed, restrict HTTP access to the administrative API endpoints from untrusted networks and disable or remove the hardcoded account. Check access logs for use of the 'b' account and for activity matching the watchTowr pre-auth RCE chain (cache poisoning chained with the hardcoded account), and prioritize remediation given the 55.3% EPSS score.

Affected
Sitecore Experience Manager (XM)10.1 to 10.1.4 rev. 011974 PRE; all 10.2 versions; 10.3 to 10.3.3 rev. 011967 PRE; 10.4 to 10.4.1 rev. 011941 PRE
Sitecore Experience Platform (XP)10.1 to 10.1.4 rev. 011974 PRE; all 10.2 versions; 10.3 to 10.3.3 rev. 011967 PRE; 10.4 to 10.4.1 rev. 011941 PRE
Sitecore Experience CommerceDeployments built on the affected XM/XP versions (10.1 to 10.4.1 ranges above)
Sitecore Managed CloudHosted XM/XP deployments on the affected 10.1 to 10.4.1 ranges above
Estimated exposure
largetens of thousands of internet-exposed Sitecore XP/XM deployments (estimate) — Sitecore XP/XM is a widely deployed enterprise CMS with thousands of large-organization customers and the affected 10.1-10.4.1 range spans the currently deployed release line, so an order of magnitude of tens of thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

Vendors
sitecore
Products
experience commerce, experience manager, experience platform, managed cloud
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news