Junglewise Threat Intelligence

CVE-2026-69225: Esri Portal for ArcGIS information disclosure via HTTP response reflection

CVE-2026-69225 · Severity: medium · CVSS 5.9 · Published 2026-08-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Esri Portal for ArcGIS is an enterprise web application used to manage geospatial data and services across organizations. An unauthenticated remote attacker can trigger the application to reflect sensitive information in HTTP responses, potentially exposing configuration details, authentication tokens, or other confidential data to unauthorized parties.

Technical details

This is an information disclosure vulnerability affecting Portal for ArcGIS versions 11.5 through 12.0. The vulnerability allows a remote, unauthenticated attacker to cause sensitive information to be reflected in HTTP response bodies. No authentication is required to exploit this flaw. The attack is network-accessible and likely involves crafting specific requests that cause the application to echo back sensitive data. Patches for affected versions should be available from Esri.

Affected products

  • Esri Portal for ArcGIS 11.5 through 12.0

Timeline

  • 2026-08-21: disclosed

References

Related threats