Skip to content
Threat Feed

Tag

Esri

6 briefs RSS
high advisory

Multiple Vulnerabilities in ESRI ArcGIS Allow Privilege Escalation and Security Bypass

Multiple unpatched vulnerabilities in ESRI ArcGIS allow a remote, anonymous attacker to bypass security measures or gain elevated user rights, potentially leading to unauthorized access and privilege escalation within affected systems.

ArcGIS vulnerability esri privilege-escalation defense-evasion
3t
high advisory

CVE-2026-13020: Weak Password Recovery in Esri Portal for ArcGIS Leading to Account Takeover

A critical vulnerability (CVE-2026-13020) exists in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes, where a weak password recovery mechanism allows a remote, unauthorized attacker to assume ownership of a user's account by exploiting this flaw.

Portal for ArcGIS <= 12.1 vulnerability web-application account-takeover esri
2t 1c
critical advisory

Critical Unauthenticated API Access in Esri Portal for ArcGIS (CVE-2026-13019)

A critical missing authentication vulnerability (CVE-2026-13019) in Esri Portal for ArcGIS versions 12.1 and earlier allows a remote, unauthenticated attacker to access unprotected critical APIs, impacting deployments on Windows, Linux, and Kubernetes environments.

Portal for ArcGIS 12.1 and earlier vulnerability esri arcgis unauthenticated-access api-security rce
1t 1c
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
critical advisory

Esri Portal for ArcGIS Incorrect Authorization Vulnerability (CVE-2026-33519)

CVE-2026-33519 is a critical vulnerability in Esri Portal for ArcGIS 11.4, 11.5, and 12.0, where incorrect authorization checks on developer credentials can lead to unauthorized privilege escalation on Windows, Linux, and Kubernetes deployments.

esri arcgis privilege-escalation incorrect-authorization cve-2026-33519 webserver
2r 1t 1c
high advisory

Esri Portal for ArcGIS Privilege Escalation via CVE-2026-33518

Esri Portal for ArcGIS 11.5 on Windows and Linux is vulnerable to privilege escalation (CVE-2026-33518), allowing highly privileged users to create developer credentials with excessive permissions.

Portal for ArcGIS esri arcgis privilege-escalation CVE-2026-33518 vulnerability
2r 1t 1c