File Upload Vulnerability in ArcGIS Server by Esri
CVE-2025-67707

5.6MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
31 December 2025

What is CVE-2025-67707?

ArcGIS Server, utilized for mapping and geographic information system (GIS) purposes, is vulnerable due to improper file validation mechanisms. This allows unauthorized remote attackers to upload arbitrary files, potentially leading to significant security breaches. Effective exploitation of this vulnerability may enable attackers to compromise server integrity, execute malicious code, or manipulate sensitive data. It is crucial for users of affected versions to apply the necessary patches and enhance their security posture to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ArcGIS Server Windows 10.9.1 <= 11.5

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.