Executive brief
A security flaw in the password recovery system of Esri Portal for ArcGIS allows unauthorized individuals to take over user accounts. Portal for ArcGIS is a central platform used by organizations to manage and share geographic data and maps. If exploited, an attacker could gain full access to a user's account, potentially leading to the theft of sensitive location data or disruption of mapping services.
Technical details
A vulnerability classified as CWE-640 (Weak Password Recovery Mechanism) exists in Esri Portal for ArcGIS. The flaw allows a remote, unauthenticated attacker to manipulate the 'forgot password' workflow to reset and take over accounts. While the attack complexity is rated as high, a successful exploit results in a complete loss of confidentiality, integrity, and availability for the affected user account. The vulnerability affects versions 12.1 and earlier across Windows, Linux, and Kubernetes deployments. Administrators are advised to configure a formal email server within ArcGIS Enterprise to facilitate secure self-service password recovery.
Affected products
- Esri Portal for ArcGIS <= 12.1
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory