CVE-2023-26262: Malicious File Upload
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26262?
CVE-2023-26262 is a vulnerability in Sitecore XP/XM 10.3 that allows an authenticated user to upload a language file and execute arbitrary code on the content management (CM) server.
How severe is CVE-2023-26262?
CVE-2023-26262 has a severity rating of 7.2, which is considered high.
How can the CVE-2023-26262 vulnerability be exploited?
The CVE-2023-26262 vulnerability can be exploited by an authenticated Sitecore user who uploads a language file containing malicious code.
What is the affected software version of CVE-2023-26262?
The affected software version of CVE-2023-26262 is Sitecore Experience Manager and Sitecore Experience Platform up to version 10.3.
Is there a fix available for CVE-2023-26262?
Yes, Sitecore has released a fix for CVE-2023-26262. It is recommended to upgrade to the latest version of Sitecore XP/XM.