Executive brief
Esri Portal for ArcGIS is a web-based platform used to manage and share geographic information and mapping applications across enterprises. A stored cross-site scripting (XSS) vulnerability in versions 11.5 and earlier allows a privileged attacker to inject malicious JavaScript code that executes in other users' browsers, potentially enabling account hijacking, credential theft, or unauthorized actions performed on behalf of victims.
Technical details
This is a stored cross-site scripting (XSS) vulnerability affecting Esri Portal for ArcGIS versions 11.5 and prior. The vulnerability allows a remote, privileged attacker to inject malicious JavaScript that persists in the application and executes in victims' browsers when they access the affected content. Stored XSS of this nature typically requires an authenticated attacker with elevated privileges to inject the payload, but once stored, any user accessing that content becomes vulnerable. The attack can result in arbitrary JavaScript execution, session hijacking, or credential harvesting. Users should upgrade to the latest long-term support release; patches are available for Enterprise versions 11.1, 11.3, and 11.5.
Affected products
- Esri Portal for ArcGIS 11.5 and prior
Timeline
- 2026-08-21: disclosed