CVE-2025-2538
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-2538 is a hardcoded credential vulnerability affecting Esri Portal for ArcGIS versions 11.4 and below. This issue arises from a specific deployment pattern and grants remote authenticated attackers the ability to elevate their privileges and obtain administrative access to the system. Successful exploitation of this weakness could lead to significant security implications, including unauthorized system modification or data exfiltration. Organizations utilizing the affected versions are strongly encouraged to apply the available patches to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Esri Portal for ArcGIS
Affected Vendors
- Esri