Security researchers have issued a warning about a pre-authentication exploit chain affecting a CMS used by some of the biggest companies in the world. Sitecore Experience Platform is a content management system (CMS) used by United Airlines, Procter & Gamble, Microsoft, Fujitsu, and more. Today, the team at watchTowr disclosed three distinct vulnerabilities that could be chained together to achieve full system takeover. There are seven vulnerabilities in total, only three of which were disclosed today, since customers have had time to apply patches. The other four flaws are not yet fixed, so these will be publicized at a later date. WatchTowr started looking at Sitecore in February, and at the time the vulnerabilities were reported, they affected the latest available version. The bugs don't have CVE identifiers yet, nor do they have severity assessment scores, but to offer an indication, one is a hardcoded credentials issue in which internal account passwords are set to a single letter, and the other is path traversal – one of the so-called unforgiveable vulnerability classes. The hardcoded password of internal accounts was found to be set to "b," which the researchers brute forced in three seconds. "This is sadly not a joke," the team blogged. The "b" refers to an old default configuration for Sitecore admin accounts, the passwords for which were always set as "b," although this is no longer the case. "The reality is that most users, especially enterprises that leverage Sit...
Sitecore CMS flaw let attackers brute-force 'b' for backdoor
The Register
·Connor Jones
·Published Jun 17, 2025
·Updated
Affected Software
1 affected component
Sitecore Experience Platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses security vulnerabilities in the Sitecore Experience Platform that allow for a pre-authentication exploit chain.
2
What security implications are discussed in the article?
The implications include potential unauthorized access and the ability for attackers to use brute-force methods to exploit the CMS.
3
What products or software are affected by the reported vulnerabilities?
The vulnerabilities affect the Sitecore Experience Platform, a widely used content management system.
4
Who are some of the major companies using the affected CMS?
Major companies using the Sitecore Experience Platform include United Airlines, Procter & Gamble, Microsoft, and Fujitsu.
5
What type of vulnerability is highlighted in this security alert?
The alert highlights a zero-day vulnerability that can be exploited without prior authentication.