Executive brief
Esri ArcGIS Server, a platform for sharing geographic information and maps, contains a security flaw in its login process. An attacker can trick a user into clicking a malicious link that redirects them from the legitimate ArcGIS login page to an untrusted, fraudulent website. This could be used in phishing campaigns to deceive users, though it does not allow the attacker to compromise the server itself or access internal data directly.
Technical details
An open redirect vulnerability exists in ArcGIS Server 11.5 due to insufficient input validation within the login redirection workflow. By crafting a specific request, a remote attacker can cause the application to redirect a user's browser to an arbitrary external URL after authentication. This is a client-side navigation issue that remains confined to the same security boundary, meaning no server-side compromise or cross-component impact is possible. Exploitation requires user interaction, typically in the form of a user clicking a malicious link. While the advisory mentions an 'authenticated attacker' in the description, the provided CVSS vector (PR:N) suggests no special privileges are required to craft the malicious link.
Affected products
- Esri ArcGIS Server 11.5
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory