CVE-2025-57878
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2025-57878 is an unvalidated redirect (open redirect) vulnerability in Esri Portal for ArcGIS versions 11.4 and below that allows a remote, unauthenticated attacker to craft a malicious URL redirecting victims to an arbitrary website, facilitating phishing attacks. Affected versions span from 10.9.1 through 11.4, including various intermediate security update releases. The vulnerability was published on September 29, 2025, with a patch made available via Esri's Security 2025 Update 3. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Blog).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), arising from insufficient validation of user-supplied URL parameters in the Portal for ArcGIS web application. An unauthenticated remote attacker can craft a specially formed URL hosted on a legitimate Portal for ArcGIS instance that, when clicked by a victim, silently redirects the browser to an attacker-controlled domain. Exploitation requires no privileges and only user interaction (clicking the crafted link), making it straightforward to weaponize in social engineering or spear-phishing campaigns (Esri Blog).

Impact

Successful exploitation allows an attacker to redirect authenticated or unauthenticated Portal for ArcGIS users to arbitrary external websites, enabling credential harvesting, malware delivery, or other phishing-based attacks. The vulnerability has low confidentiality and integrity impacts (e.g., stolen credentials or session tokens if victims enter data on a spoofed site) and no direct availability impact. Because the redirect originates from a trusted Esri domain, victims are more likely to trust and interact with the malicious destination, increasing the effectiveness of social engineering attacks (Esri Blog).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.028%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to induce a victim to click a crafted URL, limiting opportunistic mass exploitation (Esri Blog).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Portal for ArcGIS instances running version 11.4 or below using search engines, Shodan, or Censys, targeting organizations that use Esri GIS infrastructure.
  2. Craft malicious URL: Construct a URL using the legitimate Portal for ArcGIS domain that includes a redirect parameter pointing to an attacker-controlled phishing site (e.g., https://portal.victim.org/arcgis/sharing/rest/...?redirect_uri=https://attacker.com/fake-login).
  3. Deliver the link: Send the crafted URL to targeted Portal users via email, messaging platforms, or other channels, leveraging the trusted Esri domain to increase credibility.
  4. Victim interaction: When the victim clicks the link, their browser is redirected from the legitimate Portal domain to the attacker's site without warning.
  5. Achieve objective: The attacker's phishing page harvests credentials, session tokens, or other sensitive information entered by the victim, or delivers malware (Esri Blog).

Indicators of compromise

  • Network: Outbound HTTP redirects (301/302 responses) from Portal for ArcGIS endpoints to external, non-Esri domains; unusual referrer headers in web server logs showing Portal URLs as the source of traffic to unknown external sites.
  • Logs: Portal for ArcGIS access logs showing requests to redirect-capable endpoints with external URLs in query parameters (e.g., redirect_uri, returnUrl, or similar parameters pointing to non-organizational domains).
  • User Reports: End users reporting unexpected redirects to unfamiliar websites after clicking links that appeared to originate from the organization's Portal for ArcGIS instance.

Mitigation and workarounds

Esri has released patches addressing this vulnerability as part of the Portal for ArcGIS Security 2025 Update 3. Administrators should update all affected instances (versions 10.9.1 through 11.4) to the corresponding patched security update release (e.g., 11.4-security_2025_update3 or equivalent for older supported versions). As a complementary measure, organizations should conduct user awareness training to help Portal users recognize suspicious links, even those appearing to originate from trusted Esri domains (Esri Blog).

Additional resources

  • Esri Blog — Esri's official security patch advisory for Portal for ArcGIS Security 2025 Update 3
  • ENISA EUVD — European Union Vulnerability Database entry for EUVD-2025-31609
  • INCIBE Advisory — Spanish national CERT vulnerability alert for CVE-2025-57878

SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69236MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69235MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesAug 21, 2026
CVE-2026-69234MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesAug 21, 2026
CVE-2026-69237LOW3.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesAug 21, 2026
CVE-2026-69238LOW3.5
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management