Executive brief
Esri Portal for ArcGIS is a web application used to manage geographic information systems and spatial data across enterprises. A stored cross-site scripting vulnerability allows authenticated attackers with elevated privileges to inject malicious JavaScript that executes in other users' browsers, potentially enabling credential theft, session hijacking, or unauthorized actions within the portal.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS affecting versions 11.5 and earlier. The vulnerability allows a remote, privileged attacker to inject malicious code into the application that persists and executes in victims' browsers when they access the affected component. Attack requires authentication and elevated privileges, limiting the threat actor pool. Successful exploitation can result in arbitrary JavaScript execution within the victim's browser context, enabling session hijacking, credential theft, or unauthorized administrative actions. Patches are available; users are advised to upgrade to the latest long-term support release.
Affected products
- Esri Portal for ArcGIS 11.5 and prior
Timeline
- 2026-08-21: disclosed