CVE-2024-51954: Esri Arcgis Server
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.
Affected products
- Esri Arcgis Server: from 10.9.1, up to and including 11.3
Published 2025-03-03. Last modified 2026-06-17.