File Upload Vulnerability in ArcGIS Server by Esri
CVE-2025-67706
5.6MEDIUM
What is CVE-2025-67706?
ArcGIS Server versions 11.5 and earlier on both Windows and Linux platforms exhibit a critical flaw in their file upload mechanism, permitting remote attackers to leverage this weakness to upload unauthorized files. This vulnerability arises from inadequate validation of uploaded files, leading to potential exploitation by injecting malicious content into the server environment.
Affected Version(s)
ArcGIS Server Windows 10.9.1 <= 11.4
