CVE-2025-57870

CRITICAL

Esri ArcGIS Server 11.3-11.5 - Unauthenticated SQL Injection via Feature Service Operation

Title source: llm
STIX 2.1

Description

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

Scores

CVSS v3 10.0
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
esri/arcgis_server 11.3 - 11.5
Published Oct 22, 2025
Tracked Since Feb 18, 2026