Executive brief
ArcGIS Server, a platform used for creating and managing geographic information system (GIS) services, contains a security flaw in a hidden administrative component. An unauthorized person could send a specifically formatted request to this component without needing a password. If successful, this could allow the attacker to disrupt the web-based interface used to browse and access maps and data services.
Technical details
An improper authentication vulnerability (CWE-287) exists in an undocumented administrative endpoint within Esri ArcGIS Server. The flaw allows a remote, unauthenticated attacker to bypass security controls by sending a specially crafted network request to the affected endpoint. Successful exploitation can lead to the disruption of the web-based browsing interface, impacting the integrity of the management console. This issue affects ArcGIS Server version 12.0 and all prior versions. Users are advised to consult the Esri April 2026 security bulletin for remediation steps.
Affected products
- Esri ArcGIS Server 12.0 and earlier
Timeline
- 2026-05-20: disclosed: Initial publication of CVE-2026-2812
- 2026-05-20: advisory