Back

MEDIUM

Reflected XSS vulnerability in ArcGIS Server.

Published Dec 31, 2025

Description

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Esri
Published Dec 31, 2025
Updated Jan 2, 2026
Reserved Dec 10, 2025

CISA Vulnrichment

Updated Jan 2, 2026

NVD

Status Analyzed
Modified Sep 23, 2026

Red Hat

No data

ENISA EUVD

Assigner Esri
Published Dec 31, 2025
Updated Jan 2, 2026

GitHub

No data