CVE-2024-25693: Esri Portal For Arcgis

Critical severity, CVSS 9.9. EPSS: 1.3% chance of exploitation in the next 30 days.

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

Affected products

  • Esri Portal For Arcgis: up to and including 11.2

Published 2024-04-04. Last modified 2026-06-17.