CVE-2025-34509: Sitecore Experience Commerce

High severity, CVSS 7.5. EPSS: 55.9% chance of exploitation in the next 30 days.

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

Affected products

  • Sitecore Experience Commerce: from 9.0, up to and including 10.4
  • Sitecore Experience Manager: from 9.0, up to and including 10.4
  • Sitecore Experience Platform: from 9.0, before 10.4 (fixed in 10.4); version 10.4 only
  • Sitecore Managed Cloud: affected versions not specified

Published 2025-06-17. Last modified 2026-06-17.