• News/
  • https://www.theregister.com/2025/06/17/sitecore_rce_vulnerabilities/

Sitecore CMS flaw let attackers brute-force 'b' for backdoor

The Register
·
Connor Jones
·
Published Jun 17, 2025
·
Updated

Security researchers have issued a warning about a pre-authentication exploit chain affecting a CMS used by some of the biggest companies in the world. Sitecore Experience Platform is a content management system (CMS) used by United Airlines, Procter & Gamble, Microsoft, Fujitsu, and more. Today, the team at watchTowr disclosed three distinct vulnerabilities that could be chained together to achieve full system takeover. There are seven vulnerabilities in total, only three of which were disclosed today, since customers have had time to apply patches. The other four flaws are not yet fixed, so these will be publicized at a later date. WatchTowr started looking at Sitecore in February, and at the time the vulnerabilities were reported, they affected the latest available version. The bugs don't have CVE identifiers yet, nor do they have severity assessment scores, but to offer an indication, one is a hardcoded credentials issue in which internal account passwords are set to a single letter, and the other is path traversal – one of the so-called unforgiveable vulnerability classes. The hardcoded password of internal accounts was found to be set to "b," which the researchers brute forced in three seconds. "This is sadly not a joke," the team blogged. The "b" refers to an old default configuration for Sitecore admin accounts, the passwords for which were always set as "b," although this is no longer the case. "The reality is that most users, especially enterprises that leverage Sit...

Read full article

Affected Software

1 affected component
Sitecore Experience Platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security vulnerabilities in the Sitecore Experience Platform that allow for a pre-authentication exploit chain.

2

What security implications are discussed in the article?

The implications include potential unauthorized access and the ability for attackers to use brute-force methods to exploit the CMS.

3

What products or software are affected by the reported vulnerabilities?

The vulnerabilities affect the Sitecore Experience Platform, a widely used content management system.

4

Who are some of the major companies using the affected CMS?

Major companies using the Sitecore Experience Platform include United Airlines, Procter & Gamble, Microsoft, and Fujitsu.

5

What type of vulnerability is highlighted in this security alert?

The alert highlights a zero-day vulnerability that can be exploited without prior authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203