Junglewise Threat Intelligence

CVE-2026-2812: Esri ArcGIS Server improper authentication in administrative endpoint

CVE-2026-2812 · Severity: medium · CVSS 5.3 · Published 2026-05-20

Technologies: Esri ArcGIS Server. Vendors: Esri.

Executive brief

ArcGIS Server, a platform used for creating and managing geographic information system (GIS) services, contains a security flaw in a hidden administrative component. An unauthorized person could send a specifically formatted request to this component without needing a password. If successful, this could allow the attacker to disrupt the web-based interface used to browse and access maps and data services.

Technical details

An improper authentication vulnerability (CWE-287) exists in an undocumented administrative endpoint within Esri ArcGIS Server. The flaw allows a remote, unauthenticated attacker to bypass security controls by sending a specially crafted network request to the affected endpoint. Successful exploitation can lead to the disruption of the web-based browsing interface, impacting the integrity of the management console. This issue affects ArcGIS Server version 12.0 and all prior versions. Users are advised to consult the Esri April 2026 security bulletin for remediation steps.

Affected products

  • Esri ArcGIS Server 12.0 and earlier

Timeline

  • 2026-05-20: disclosed: Initial publication of CVE-2026-2812
  • 2026-05-20: advisory

References

Related threats