CVE-2025-57879
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2025-57879 is an unvalidated redirect (open redirect) vulnerability in Esri Portal for ArcGIS versions 11.4 and below that allows a remote, unauthenticated attacker to craft a URL redirecting victims to arbitrary websites, facilitating phishing attacks. Affected versions span 10.9.1, 11.0, 11.1, 11.2, 11.3, and 11.4, including various intermediate security update releases. The vulnerability was published on September 29, 2025, and a patch was made available via the Portal for ArcGIS Security 2025 Update 3 patch. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), arising from insufficient validation of user-supplied redirect URL parameters within the Portal for ArcGIS web application. An unauthenticated remote attacker can craft a specially formed URL hosted on the legitimate Portal for ArcGIS domain that, when followed by a victim, silently redirects them to an attacker-controlled website. Exploitation requires no privileges and only necessitates that the victim click the crafted link (user interaction required). No public proof-of-concept code has been identified at this time (Esri Advisory).

Impact

The primary impact of this vulnerability is on confidentiality and integrity at a limited level — attackers can leverage the trusted reputation of the Portal for ArcGIS domain to deceive users into visiting malicious websites, enabling credential harvesting, malware delivery, or other phishing-based attacks. Because the redirect originates from a trusted organizational domain, victims are more likely to trust and follow the link, increasing the effectiveness of social engineering campaigns. Availability is not impacted, and direct system compromise is not possible through this vulnerability alone (Esri Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-57879. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.028%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported (Esri Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Portal for ArcGIS instances running versions 10.9.1 through 11.4 using search engines, Shodan, or organizational asset inventories.
  2. Identify redirect parameter: Locate URL parameters within the Portal for ArcGIS web interface that accept redirect destinations (e.g., redirect, returnUrl, or similar query parameters) without proper validation.
  3. Craft malicious URL: Construct a URL pointing to the legitimate Portal for ArcGIS domain but including a redirect parameter value pointing to an attacker-controlled site (e.g., https://portal.example.com/arcgis/home/signin.html?redirect=https://attacker.com/fake-login).
  4. Deliver to victim: Distribute the crafted URL via email, messaging platforms, or other phishing vectors, leveraging the trusted domain to increase victim confidence.
  5. Harvest credentials or deliver malware: When the victim clicks the link and is redirected to the attacker-controlled site, capture credentials via a spoofed login page or deliver a malicious payload (Esri Advisory).

Indicators of compromise

  • Network: HTTP requests to Portal for ArcGIS endpoints containing redirect or return URL parameters pointing to external or unexpected domains; outbound redirects (HTTP 301/302 responses) from the portal to non-organizational domains.
  • Logs: Web server or application access logs showing requests with redirect parameters containing external URLs (e.g., redirect=https:// pointing to domains outside the organization); unusual referrer chains in proxy logs originating from the portal domain.
  • User Reports: End-user reports of being unexpectedly redirected to unfamiliar websites after clicking links that appeared to originate from the organization's ArcGIS portal.

Mitigation and workarounds

Esri has released the Portal for ArcGIS Security 2025 Update 3 patch, which addresses this vulnerability across affected versions (10.9.1, 11.1, 11.2, 11.3, and 11.4). Organizations should apply this patch as soon as possible. As interim measures, administrators should implement user awareness training on phishing risks and suspicious URLs, and consider deploying web application firewall (WAF) rules to detect and block requests containing external redirect destinations in URL parameters (Esri Advisory).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13020CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-13019CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-33519CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2026-33518HIGH7.2
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2025-57879MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesSep 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management