PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-34509

7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
experience managerexperience platform
Updated Sep 25, 2026View on NVD →
S4E scanner

CVE history: experience manager

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →