Junglewise Threat Intelligence

CVE-2025-57870: A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability

CVE-2025-57870 · Severity: critical · CVSS 10 · Published 2025-10-22

Technologies: Microsoft Windows, Esri ArcGIS Server, Linux Kernel, Kubernetes. Vendors: Microsoft, Esri, Linux, Kubernetes.

Executive brief

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

Affected products

  • Microsoft Windows
  • esri ArcGIS Server
  • Linux linux_kernel
  • kubernetes kubernetes

Related threats