CVE-2025-2538: Esri Portal For Arcgis
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
Affected products
- Esri Portal For Arcgis: up to and including 11.4
Published 2025-03-20. Last modified 2026-06-17.