External risk intelligence

Esri ArcGIS Server SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-57870

ArcGIS Server is commonly deployed as an internet-facing service to host and share feature services and geospatial data. Because these services are designed to be accessed by web and mobile clients over the network, they are frequently exposed to the public internet.

SQL Injection

Esri Arcgis Server

11.3 to 11.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A SQL injection vulnerability has been identified in ArcGIS Server, affecting recent versions. This flaw could permit an unauthenticated attacker to execute commands, potentially leading to unauthorized access, alteration, or deletion of sensitive geospatial data within the enterprise geodatabase.

  • Attackers can inject harmful commands.
  • Significant risk to enterprise data integrity.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted SQL commands through a specific ArcGIS Feature Service operation. This operation is accessible over the network without requiring any authentication. If successful, the attacker could gain unauthorized control over the database, allowing them to view, alter, or erase sensitive information.

  • No authentication required for access.
  • Triggered via specific Feature Service operation.
  • Allows unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

A SQL Injection vulnerability in ArcGIS Server could allow an unauthenticated remote attacker to run arbitrary SQL commands through a specific Feature Service operation. This may lead to unauthorized access to, modification of, or deletion of data stored in the underlying Enterprise Geodatabase.

  • Enterprise Geodatabase data.
  • Via a specific Feature Service operation.
  • Data could be accessed or altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the SQL Injection vulnerability in Esri ArcGIS Server, the primary responsibility for remediation likely falls to the platform or infrastructure teams managing the ArcGIS Server deployments, in coordination with application owners who depend on these services. The first practical step is to identify all instances of ArcGIS Server, confirm their network exposure and business criticality, and then engage the accountable owners to plan remediation, which may involve vendor coordination or temporary risk reduction measures.

  • Own the issue, confirm exposure, and plan.
  • Verify affected ArcGIS Server instances.
  • Coordinate remediation with Esri.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Esri ArcGIS Server?

Esri ArcGIS Server is a software component used to host, manage, and share geospatial data and mapping services. It enables organizations to publish feature services that web or mobile applications can query and interact with, effectively serving as the backend engine for enterprise-level location intelligence and spatial analysis tasks.

What does SQL injection mean for CVE-2025-57870?

This vulnerability is classified as CWE-89 (SQL Injection). It occurs when an application fails to properly sanitize user input, allowing an attacker to insert their own SQL commands into a database query. In this case, the flaw allows unauthorized parties to manipulate the underlying Enterprise Geodatabase, potentially exposing, changing, or deleting sensitive geographic data.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specially crafted request through a specific ArcGIS Feature Service operation. Crucially, the bug is only triggered when interacting with these specific service operations; standard, non-malicious use of the server remains unaffected. Because no authentication is required, any remote user capable of communicating with the target feature service can attempt the injection.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a high-risk concern because ArcGIS Server is frequently deployed as an internet-facing service to support public-facing maps and apps. Since these services are designed for broad network accessibility, they are often directly reachable by external actors, which significantly increases the likelihood that a vulnerable server will be identified and targeted.

What should I do if I run ArcGIS Server?

First, inventory your network to identify all instances of ArcGIS Server 11.3 through 11.5. Once identified, confirm which instances are accessible from the internet and evaluate their business criticality. Engage with the platform owners immediately to coordinate with Esri and implement the necessary patches or security updates to protect your enterprise geodatabase from unauthorized access.

References