
Information Disclosure in ItemService API with a restricted anonymous user, leading to exposure of cache keys using a brute-force approach
The ItemService API, accessible at /sitecore/shell/api/sitecore/ItemService/GetChildren, allows unauthenticated users to query the Sitecore database. By providing a valid item GUID and database name, an attacker can enumerate the internal structure of the Sitecore instance, including sensitive information about items, templates, and system configuration.
Information Disclosure: The attacker uses CVE-2025-53694 to gather information about the target system.
Sitecore has released patches for this vulnerabilitie. It is strongly recommended to upgrade to the latest version of Sitecore XP or apply the provided security patches.
[1] Watchtowr Labs. (2025). Cache Me If You Can: Sitecore Experience Platform Cache Poisoning to RCE.