CVE-2025-34139: Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34139?
CVE-2025-34139 is considered a critical vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-34139?
To fix CVE-2025-34139, update all affected Sitecore products including Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud to the latest versions.
Who is affected by CVE-2025-34139?
CVE-2025-34139 affects all installations of Sitecore Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud versions between 8.0 and 10.4 inclusive.
What are the potential impacts of CVE-2025-34139?
The impact of CVE-2025-34139 includes the risk of unauthorized users accessing and reading arbitrary files on the server.
Is there a workaround for CVE-2025-34139?
Currently, there is no specific workaround for CVE-2025-34139; the only remediation is to upgrade to the patched versions.