黑料社

Security Bulletin with an exclamation point in the center of the image
Security Bulletin with an exclamation point in the center of the image

Pre-Authenticated RCE Chain Disclosed in Sitecore XP

On 17 June 2025, watchTowr disclosed technical details for a pre-authenticated remote code execution (RCE) exploit chain in Sitecore Experience 黑料社 (XP), an enterprise content management system.
Security Bulletin with an exclamation point in the center of the image
6 min read

On 17 June 2025, watchTowr disclosed technical details for a pre-authenticated remote code execution (RCE) exploit chain in Sitecore Experience 黑料社 (XP), an enterprise content management system. Although Sitecore released a fix for these vulnerabilities in May 2025, no official CVE identifiers have been assigned at this time. The three vulnerabilities are currently tracked as WT-2025-0024, WT-2025-0025, and WT-2025-0032 by watchTowr and impact Sitecore XP versions 10.1 through 10.4.?

  • WT-2025-0024 (Hardcoded ServicesAPI User Credentials): Sitecore XP contains a built-in service account with a hardcoded password, enabling unauthenticated attackers to bypass authentication and gain unauthorised access.?
  • WT-2025-0025 (Post-Authentication RCE via Sitecore PowerShell Extension): The Sitecore PowerShell Extensions module’s file upload lacks proper validation, letting authenticated threat actors upload malicious files that enable RCE.?
  • WT-2025-0032 (Post-Authentication RCE via Path Traversal): An upload feature vulnerable to path traversal allows authenticated threat actors to upload a crafted ZIP file containing malicious code, which leads to RCE.?

While Arctic Wolf has not observed exploitation of these vulnerabilities in the wild, Sitecore vulnerabilities have been exploited in the past, as noted in CISA’s Known Exploited Vulnerabilities (KEV) catalog. With technical details now publicly available, threat actors may attempt to develop exploits in the near future.?

Recommendation?

Upgrade to Latest Fixed Version

Arctic Wolf strongly recommends that customers upgrade to the latest fixed version.?

Product? Affected Versions? Fixed Version?
Sitecore XP? 10.1 – 10.4? 10.4 ()?

 

Please follow your organisation’s patching and testing guidelines to minimise potential operational impact.?

References?

Resources

Understand the threat landscape, and how to better defend your organisation, with the 2025 Arctic Wolf Threat Report

See how Arctic Wolf utilises threat intelligence to harden your attack surface and stop threats earlier and faster

Share this post: