PT-2025-54464 · Esri · Arcgis Server

Published

2025-12-31

·

Updated

2026-02-19

·

CVE-2025-67706

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ArcGIS Server versions 11.5 and earlier
Description ArcGIS Server on Windows and Linux does not properly validate uploaded files, potentially allowing remote attackers to upload arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-67706

Affected Products

Arcgis Server