Junglewise Threat Intelligence

CVE-2026-69224: Esri Portal for ArcGIS information disclosure in HTTP response

CVE-2026-69224 · Severity: medium · CVSS 5.9 · Published 2026-08-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Esri Portal for ArcGIS is a web-based application used by organizations to publish, manage, and share geographic data and mapping services. An information disclosure vulnerability in versions 12.0 and earlier allows unauthenticated attackers to potentially extract sensitive information through HTTP responses, though the attack conditions are difficult to reproduce. This could lead to exposure of confidential data or system details that could aid further attacks.

Technical details

The vulnerability is an information disclosure flaw in Esri Portal for ArcGIS 12.0 and earlier that permits remote, unauthenticated attackers to reflect sensitive data in HTTP response bodies under difficult-to-reproduce circumstances. The precise attack mechanism is unclear from available documentation, but it appears to involve an input validation or improper output encoding issue in a web handler. An attacker can potentially craft requests to trigger the vulnerability and obtain sensitive information without authentication, though reproduction is not straightforward. The affected versions are 12.0 and earlier; users are advised to upgrade to patched versions.

Affected products

  • Esri Portal for ArcGIS 12.0 and earlier

Timeline

  • 2026-08-21: disclosed

References

Related threats