CVE-2025-34139
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-25

Last updated on: 2025-11-12

Assigner: VulnCheck

Description
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-25
Last Modified
2025-11-12
Generated
2026-05-07
AI Q&A
2025-07-25
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
sitecore experience_manager *
sitecore experience_commerce *
sitecore experience_platform *
sitecore managed_cloud *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an arbitrary file read issue in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud versions from 8.0 Initial Release through 10.4 Initial Release and later. It allows an unauthenticated attacker to read arbitrary files on affected systems, including Content Management and standalone instances, as well as PaaS and containerized deployments. The attack can be performed remotely without any privileges or user interaction and has a high impact on confidentiality. [1]


How can this vulnerability impact me? :

This vulnerability can impact you by allowing an attacker to read arbitrary files on your Sitecore systems, potentially exposing sensitive information stored in those files. Since the attacker does not need any privileges or user interaction, the risk of data leakage is significant, which could lead to unauthorized disclosure of confidential data. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart