CVE-2023-26262: Sitecore Experience Manager
High severity, CVSS 7.2. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
Affected products
- Sitecore Experience Manager: up to and including 10.3
- Sitecore Experience Platform: before 10.3 (fixed in 10.3)
Published 2023-03-14. Last modified 2026-06-17.