CVE-2025-34509

HIGH EXPLOITED NUCLEI

Sitecore XP/XM 10.1-10.1.4, 10.2, 10.3-10.3.3, 10.4-10.4.1 - Unauthenticated RCE via Hardcoded Credentials

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-34509 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Piotr Bazydlo, msutovsky-r7, including a Metasploit module exploits/windows/http/sitecore_xp_cve_2025_34510. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits CVE-2025-34510, a path traversal vulnerability in Sitecore XP, leading to remote code execution. It also leverages CVE-2025-34509 (hardcoded credentials) for authentication.

Description

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Piotr Bazydlo, msutovsky-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sitecore_xp_cve_2025_34510.rb

This Metasploit module exploits CVE-2025-34510, a path traversal vulnerability in Sitecore XP, leading to remote code execution. It also leverages CVE-2025-34509 (hardcoded credentials) for authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sitecore XP versions 10.0.0 to 10.4
Auth required
Prerequisites: Network access to the target · Sitecore XP instance with vulnerable version · Valid credentials (exploits hardcoded 'ServicesAPI:b' account)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials
HIGHVERIFIEDby daffainfo
Shodan: title:"sitecore"

References (2)

Core 2
Core References
Exploit, Third Party Advisory third-party-advisory exploit technical-description
https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/

Scores

CVSS v3 7.5
EPSS 0.1687
EPSS Percentile 95.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-06-22
CWE
CWE-798
Status published
Products (5)
sitecore/experience_commerce 9.0 - 10.4
sitecore/experience_manager 9.0 - 10.4
sitecore/experience_platform 10.4
sitecore/experience_platform 9.0 - 10.4
sitecore/managed_cloud
Published Jun 17, 2025
Tracked Since Feb 18, 2026