Junglewise Threat Intelligence

CVE-2026-69230: Esri Portal for ArcGIS stored cross-site scripting

CVE-2026-69230 · Severity: medium · CVSS 5.5 · Published 2026-08-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Portal for ArcGIS is a web-based platform that organizations use to manage, share, and collaborate on geographic data and mapping applications. An authenticated administrator with malicious intent could inject harmful JavaScript code into the system that automatically runs in other users' browsers, potentially allowing them to steal session tokens, modify data, or perform unauthorized actions on behalf of victims.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and earlier, where an administratively privileged attacker can inject malicious JavaScript code that persists in the application. This code executes in the browsers of other users who view the affected content, without requiring user interaction beyond normal portal usage. The vulnerability requires administrative privileges to exploit, limiting the threat surface to trusted or compromised admin accounts. Affected versions include ArcGIS Enterprise 11.1, 11.3, and 11.5; users should upgrade to the latest long-term support release.

Affected products

  • Esri Portal for ArcGIS 11.5 and prior

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: advisory: CVE-2026-69230

References

Related threats