Get real-time updates on Telegram
CVE-2025-57871: portal for arcgis 10.9.1, 11.0, 11.1 (+3 more affected versions); +1 more affected products
CVE-2025-57871. CVSS 3.1 base score 4.8 (MEDIUM, Vendor/CNA). EPSS 0.00222 (percentile 0.11695), scored 2026-10-08.
Affected technology
portal for arcgis · 10.9.1
esri
portal for arcgis · 10.9.1 · update security_2025_update1
esri
portal for arcgis · 10.9.1 · update security_2025_update2
esri
portal for arcgis · 11.0
esri
portal for arcgis · 11.1
esri
portal for arcgis · 11.1 · update security_2024_update1
esri
portal for arcgis · 11.1 · update security_2024_update2
esri
portal for arcgis · 11.1 · update security_2025_update1
esri
portal for arcgis · 11.1 · update security_2025_update2
esri
portal for arcgis · 11.2
esri
portal for arcgis · 11.2 · update security_2024_update1
esri
portal for arcgis · 11.2 · update security_2024_update2
esri
portal for arcgis · 11.2 · update security_2025_update1
esri
portal for arcgis · 11.2 · update security_2025_update2
esri
portal for arcgis · 11.3
esri
portal for arcgis · 11.3 · update security_2025_update1
esri
portal for arcgis · 11.3 · update security_2025_update2
esri
portal for arcgis · 11.4
esri
portal for arcgis · 11.4 · update security_2025_update1
esri
portal for arcgis · 11.4 · update security_2025_update2
esri
Portal for ArcGIS · 10.9.1 through 11.4
Esri
Description’s affected range: 11.4 and below that may
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · High privileges required · User interaction required
What an attacker can do
A remote authenticated attacker with administrative access may supply a crafted string which would execute arbitrary JavaScript code in the browser. Vendor/CNA’s CVSS 3.1 assessment (base score 4.8/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-79
- CCR priority
- 19.3 /100 (P5)
- CVSS 3.1
- 4.8 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
- EPSS
- 0.00222 · percentile 0.11695 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-57871.html