Junglewise Threat Intelligence

CVE-2026-13019: Esri Portal for ArcGIS missing authentication for critical function

CVE-2026-13019 · Severity: critical · CVSS 9.8 · Published 2026-07-07

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Esri Portal for ArcGIS, a central platform for managing and sharing geographic information, contains a critical security flaw where a sensitive administrative interface is left unprotected. This allows an unauthorized person on the network to access internal functions without a password. An attacker could potentially take full control of the system, modify geographic data, or disrupt mapping services.

Technical details

A missing authentication vulnerability exists in Esri Portal for ArcGIS (versions 12.1 and earlier) across Windows, Linux, and Kubernetes deployments. The flaw is rooted in an unprotected API that fails to validate credentials before granting access to critical functions, categorized under CWE-640 (Weak Password Recovery Mechanism). A remote, unauthenticated attacker can exploit this over the network with low complexity and no user interaction. Successful exploitation could lead to a complete compromise of confidentiality, integrity, and availability. Esri has addressed this in their June 2026 Security Bulletin.

Affected products

  • Esri Portal for ArcGIS 12.1 and earlier

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References

Related threats