Junglewise Threat Intelligence

CVE-2026-13020: Esri Portal for ArcGIS weak password recovery mechanism

CVE-2026-13020 · Severity: high · CVSS 8.1 · Published 2026-07-07

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

A security flaw in the password recovery system of Esri Portal for ArcGIS allows unauthorized individuals to take over user accounts. Portal for ArcGIS is a central platform used by organizations to manage and share geographic data and maps. If exploited, an attacker could gain full access to a user's account, potentially leading to the theft of sensitive location data or disruption of mapping services.

Technical details

A vulnerability classified as CWE-640 (Weak Password Recovery Mechanism) exists in Esri Portal for ArcGIS. The flaw allows a remote, unauthenticated attacker to manipulate the 'forgot password' workflow to reset and take over accounts. While the attack complexity is rated as high, a successful exploit results in a complete loss of confidentiality, integrity, and availability for the affected user account. The vulnerability affects versions 12.1 and earlier across Windows, Linux, and Kubernetes deployments. Administrators are advised to configure a formal email server within ArcGIS Enterprise to facilitate secure self-service password recovery.

Affected products

  • Esri Portal for ArcGIS <= 12.1

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References

Related threats