Junglewise Threat Intelligence

CVE-2026-33518: Esri Portal for ArcGIS incorrect privilege assignment

CVE-2026-33518 · Severity: critical · CVSS 9.8 · Published 2026-04-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

A security vulnerability in Esri Portal for ArcGIS, a platform used for managing and sharing geographic data, could allow certain users to gain more system permissions than intended. By creating specific developer credentials, an attacker could potentially escalate their privileges to perform unauthorized actions or access sensitive data. This could lead to a compromise of the mapping platform's integrity and the confidentiality of the geographic information it hosts.

Technical details

An incorrect privilege assignment vulnerability (CWE-266) exists in Esri Portal for ArcGIS version 11.5 on both Windows and Linux platforms. The flaw resides in the credential generation process, where highly privileged users can create developer credentials that inherit or grant more privileges than are appropriate or expected. While the vendor (Esri) indicates a CVSS 9.8 (unauthenticated), the NVD analysis suggests high privileges (PR:H) may be required to trigger the creation of these credentials. If exploited, this allows for significant privilege escalation within the portal environment. Users are advised to consult the Esri April 2026 Security Bulletin for patching information.

Affected products

  • Esri Portal for ArcGIS 11.5

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory

References