
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-57879 is an unvalidated redirect (open redirect) vulnerability in Esri Portal for ArcGIS versions 11.4 and below that allows a remote, unauthenticated attacker to craft a URL redirecting victims to arbitrary websites, facilitating phishing attacks. Affected versions span 10.9.1, 11.0, 11.1, 11.2, 11.3, and 11.4, including various intermediate security update releases. The vulnerability was published on September 29, 2025, and a patch was made available via the Portal for ArcGIS Security 2025 Update 3 patch. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), arising from insufficient validation of user-supplied redirect URL parameters within the Portal for ArcGIS web application. An unauthenticated remote attacker can craft a specially formed URL hosted on the legitimate Portal for ArcGIS domain that, when followed by a victim, silently redirects them to an attacker-controlled website. Exploitation requires no privileges and only necessitates that the victim click the crafted link (user interaction required). No public proof-of-concept code has been identified at this time (Esri Advisory).
The primary impact of this vulnerability is on confidentiality and integrity at a limited level — attackers can leverage the trusted reputation of the Portal for ArcGIS domain to deceive users into visiting malicious websites, enabling credential harvesting, malware delivery, or other phishing-based attacks. Because the redirect originates from a trusted organizational domain, victims are more likely to trust and follow the link, increasing the effectiveness of social engineering campaigns. Availability is not impacted, and direct system compromise is not possible through this vulnerability alone (Esri Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-57879. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.028%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported (Esri Advisory).
redirect, returnUrl, or similar query parameters) without proper validation.https://portal.example.com/arcgis/home/signin.html?redirect=https://attacker.com/fake-login).redirect=https:// pointing to domains outside the organization); unusual referrer chains in proxy logs originating from the portal domain.Esri has released the Portal for ArcGIS Security 2025 Update 3 patch, which addresses this vulnerability across affected versions (10.9.1, 11.1, 11.2, 11.3, and 11.4). Organizations should apply this patch as soon as possible. As interim measures, administrators should implement user awareness training on phishing risks and suspicious URLs, and consider deploying web application firewall (WAF) rules to detect and block requests containing external redirect destinations in URL parameters (Esri Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."