Tag
Multiple Vulnerabilities in ESRI ArcGIS Allow Privilege Escalation and Security Bypass
3 TTPsMultiple unpatched vulnerabilities in ESRI ArcGIS allow a remote, anonymous attacker to bypass security measures or gain elevated user rights, potentially leading to unauthorized access and privilege escalation within affected systems.
CVE-2026-13020: Weak Password Recovery in Esri Portal for ArcGIS Leading to Account Takeover
2 TTPs 1 CVEA critical vulnerability (CVE-2026-13020) exists in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes, where a weak password recovery mechanism allows a remote, unauthorized attacker to assume ownership of a user's account by exploiting this flaw.
Critical Unauthenticated API Access in Esri Portal for ArcGIS (CVE-2026-13019)
1 TTP 1 CVEA critical missing authentication vulnerability (CVE-2026-13019) in Esri Portal for ArcGIS versions 12.1 and earlier allows a remote, unauthenticated attacker to access unprotected critical APIs, impacting deployments on Windows, Linux, and Kubernetes environments.
CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server
2 TTPs 1 IOCAn unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.
Esri Portal for ArcGIS Incorrect Authorization Vulnerability (CVE-2026-33519)
2 rules 1 TTP 1 CVECVE-2026-33519 is a critical vulnerability in Esri Portal for ArcGIS 11.4, 11.5, and 12.0, where incorrect authorization checks on developer credentials can lead to unauthorized privilege escalation on Windows, Linux, and Kubernetes deployments.
Esri Portal for ArcGIS Privilege Escalation via CVE-2026-33518
2 rules 1 TTP 1 CVEEsri Portal for ArcGIS 11.5 on Windows and Linux is vulnerable to privilege escalation (CVE-2026-33518), allowing highly privileged users to create developer credentials with excessive permissions.