A pre‑auth flaw in Sitecore’s XAML handler allows attackers to invoke an unsafe path and poison HTML cache entries. When paired with exposed ItemService API endpoints that reveal cacheable items and key variants, attackers can reliably overwrite cached content and hijack rendered pages on affected instances.
The IONIX threat lab ran a safe exploitability test on all relevant assets. The number of confirmed findings indicates how many assets can be exploited.
References:

