Executive brief
Esri Portal for ArcGIS, a central platform for managing and sharing geographic information, contains a critical security flaw in how it handles developer credentials. An attacker could exploit this to gain unauthorized access to the system, potentially leading to the theft of sensitive data, modification of geographic records, or disruption of mapping services. This vulnerability affects installations on Windows, Linux, and Kubernetes environments.
Technical details
An incorrect authorization vulnerability (CWE-266) exists in Esri Portal for ArcGIS versions 11.4, 11.5, and 12.0. The software fails to correctly validate permissions assigned to developer credentials, allowing an attacker to bypass intended access controls. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation could grant an attacker full control over the portal's data and administrative functions (Confidentiality, Integrity, and Availability impact). The issue affects deployments across Windows, Linux, and Kubernetes platforms.
Affected products
- Esri Portal for ArcGIS 11.4, 11.5, 12.0
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory