Junglewise Threat Intelligence

CVE-2026-69228: Esri Portal for ArcGIS authentication bypass in resource access

CVE-2026-69228 · Severity: medium · CVSS 5.3 · Published 2026-08-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Esri Portal for ArcGIS is a web-based platform used by organizations to manage and share geospatial data and mapping applications. A missing authentication vulnerability allows remote attackers without credentials to access certain system resources that should be restricted to authenticated users, potentially exposing sensitive configuration or operational data.

Technical details

A missing authentication vulnerability exists in Esri Portal for ArcGIS versions 12.0 and prior, allowing unauthenticated remote attackers to access specific protected resources. The vulnerability stems from insufficient authentication checks on certain API endpoints or resources that should require user authentication. No user-generated content is directly compromised, but system-level resources become accessible without credentials. The attack requires only network connectivity and no user interaction. Esri recommends upgrading to the latest long-term support release to remediate this issue.

Affected products

  • Esri Portal for ArcGIS 12.0 and prior

Timeline

  • 2026-08-21: disclosed

References

Related threats