Sitecore XM and XP Hardcoded Credentials
70Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.5epss 54%
from disclosure to weapon
Published on NVDJun 17
VulnCheck+5d
exploitation probability
54%top 1% of all CVEs
observed exploitation
yesVulnCheck
In short
Sitecore XM and XP contain a hardcoded username and password built into the software. An attacker can use this account to remotely access administrative features without needing legitimate credentials, potentially compromising the entire website.
Technical detail
Sitecore XM and XP versions 10.1–10.4.1 contain hardcoded credentials (CWE-798) embedded in the application. Unauthenticated remote attackers can leverage these credentials to authenticate to administrative APIs exposed over HTTP, bypassing authentication controls and gaining unauthorized administrative access.
Summary generated and translated by AI from the official description.
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N