CVE-2025-34139

HIGH

Sitecore - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.

Scores

CVSS v4 8.7
EPSS 0.0020
EPSS Percentile 42.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522 CWE-552
Status published
Products (4)
Sitecore/Experience Commerce (XC) 8.0 Initial Release - 10.4 Initial Release and later
Sitecore/Experience Manager (XM) 8.0 Initial Release - 10.4 Initial Release and later
Sitecore/Experience Platform (XP) 8.0 Initial Release - 10.4 Initial Release and later
Sitecore/Managed Cloud 8.0 Initial Release - 10.4 Initial Release and later
Published Jul 25, 2025
Tracked Since Feb 18, 2026