← Vulnerability feed

Vulnerability record · CVE-2024-25693 · published 4 April 2024

CVE-2024-25693: Esri portal for arcgis path traversal vulnerability

Esri · Portal For Arcgis

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

9.9 CVSS 3.1 Critical EPSS 1.3% · top 31.5% CWE-22 · Path traversal
9.9CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25693 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-13019Esri portal for arcgis weak password recovery vulnerabilityEsri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability a…EPSS 0.75%9.8CVE-2026-13020Esri portal for arcgis weak password recovery vulnerabilityA Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes…EPSS 0.47%9.8CVE-2026-33519Esri portal for arcgis vulnerabilityAn incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…EPSS 0.48%9.8CVE-2025-2538Esri portal for arcgis hard-coded credentials vulnerabilityA hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remo…EPSS 0.55%9.6CVE-2022-38193Esri portal for arcgis code injection vulnerabilityThere is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass…EPSS 0.89%9.1CVE-2025-4967Esri portal for arcgis server-side request forgery (ssrf) vulnerabilityEsri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.EPSS 0.49%8.8CVE-2023-25832Esri portal for arcgis cross-site request forgery vulnerabilityThere is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authoriz…EPSS 0.27%8.8CVE-2021-29108Esri portal for arcgis improper verification of cryptographic signature vulnerabilityThere is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a rem…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2024-25693), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.