Executive brief
Esri Portal for ArcGIS is a web-based geospatial data and mapping platform used by organizations to manage and share spatial information. A stored cross-site scripting vulnerability in versions 11.5 and earlier allows authenticated administrators to inject malicious code that executes in users' browsers, potentially compromising session security and enabling credential theft or unauthorized actions on behalf of victims.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior, affecting ArcGIS Enterprise 11.1, 11.3, and 11.5. The vulnerability allows a remote attacker with administrative privileges to inject malicious JavaScript that persists in the application and executes in the browsers of other users who view the affected content. This requires administrative credentials to inject the payload, but no user interaction is needed for victims to execute the malicious code. The attack can result in session hijacking, credential theft, or unauthorized actions within the Portal environment. Patches are available and users are advised to upgrade to the latest long-term support release.
Affected products
- Esri Portal for ArcGIS 11.5 and prior
Timeline
- 2026-08-21: disclosed