Executive brief
Esri Portal for ArcGIS, a web-based platform for managing geographic information systems and enterprise mapping, contains an HTML injection vulnerability in its Home application. An authenticated user can inject malicious HTML code to alter the appearance of pages seen by other users, potentially redirecting them to fraudulent sites, stealing credentials, or spreading malware through the portal interface.
Technical details
This is an HTML injection (a form of reflected or stored cross-site scripting) vulnerability in the Portal for ArcGIS Home application. The vulnerability exists in versions 12.0 and prior, affecting ArcGIS Enterprise releases 11.1, 11.3, 11.5, and 12.0. The attack requires an authenticated attacker with access to the portal; there are no known preconditions around network accessibility beyond standard portal access. An attacker can inject arbitrary HTML to modify page content viewed by other users. A patch is available, and users are advised to upgrade to the latest long-term support release.
Affected products
- Esri Portal for ArcGIS 12.0 and prior
Timeline
- 2026-08-21: disclosed