Arbitrary File Read Vulnerability in Sitecore Experience Manager and Platform Products
CVE-2025-34139

8.7HIGH

What is CVE-2025-34139?

A critical security vulnerability affects Sitecore Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud solutions that may allow unauthorized users to read arbitrary files on the server. This vulnerability impacts multiple product versions from the initial release up to later versions, including standalone instances and various deployment modes such as PaaS and containerized options. It raises significant concerns for security professionals and organizations utilizing these platforms.

Affected Version(s)

Experience Commerce (XC) 8.0 Initial Release <= 10.4 Initial Release and later

Experience Manager (XM) 8.0 Initial Release <= 10.4 Initial Release and later

Experience Platform (XP) 8.0 Initial Release <= 10.4 Initial Release and later

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sitecore
.
CVE-2025-34139 : Arbitrary File Read Vulnerability in Sitecore Experience Manager and Platform Products