
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-57878 is an unvalidated redirect (open redirect) vulnerability in Esri Portal for ArcGIS versions 11.4 and below that allows a remote, unauthenticated attacker to craft a malicious URL redirecting victims to an arbitrary website, facilitating phishing attacks. Affected versions span from 10.9.1 through 11.4, including various intermediate security update releases. The vulnerability was published on September 29, 2025, with a patch made available via Esri's Security 2025 Update 3. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Blog).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), arising from insufficient validation of user-supplied URL parameters in the Portal for ArcGIS web application. An unauthenticated remote attacker can craft a specially formed URL hosted on a legitimate Portal for ArcGIS instance that, when clicked by a victim, silently redirects the browser to an attacker-controlled domain. Exploitation requires no privileges and only user interaction (clicking the crafted link), making it straightforward to weaponize in social engineering or spear-phishing campaigns (Esri Blog).
Successful exploitation allows an attacker to redirect authenticated or unauthenticated Portal for ArcGIS users to arbitrary external websites, enabling credential harvesting, malware delivery, or other phishing-based attacks. The vulnerability has low confidentiality and integrity impacts (e.g., stolen credentials or session tokens if victims enter data on a spoofed site) and no direct availability impact. Because the redirect originates from a trusted Esri domain, victims are more likely to trust and interact with the malicious destination, increasing the effectiveness of social engineering attacks (Esri Blog).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.028%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to induce a victim to click a crafted URL, limiting opportunistic mass exploitation (Esri Blog).
https://portal.victim.org/arcgis/sharing/rest/...?redirect_uri=https://attacker.com/fake-login).redirect_uri, returnUrl, or similar parameters pointing to non-organizational domains).Esri has released patches addressing this vulnerability as part of the Portal for ArcGIS Security 2025 Update 3. Administrators should update all affected instances (versions 10.9.1 through 11.4) to the corresponding patched security update release (e.g., 11.4-security_2025_update3 or equivalent for older supported versions). As a complementary measure, organizations should conduct user awareness training to help Portal users recognize suspicious links, even those appearing to originate from trusted Esri domains (Esri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."