Junglewise Threat Intelligence

CVE-2026-69234: Esri Portal for ArcGIS reflected cross-site scripting

CVE-2026-69234 · Severity: medium · CVSS 6.1 · Published 2026-08-21

Technologies: Esri Portal For Arcgis. Vendors: Esri.

Executive brief

Portal for ArcGIS is Esri's enterprise portal platform used by organizations to manage and share geographic data and mapping applications. A reflected cross-site scripting (XSS) vulnerability in versions 11.5 and earlier allows attackers to craft malicious links that execute arbitrary JavaScript in users' browsers, potentially stealing session credentials, data, or performing unauthorized actions on behalf of the victim.

Technical details

A reflected XSS vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior. The vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript through a crafted URL; when a user clicks the link, the malicious code executes in their browser with the user's privileges. No authentication is required to construct or distribute the exploit link, though successful exploitation depends on user interaction (clicking the link). Attackers can steal session tokens, modify data, or perform actions as the victim. Patches are available for ArcGIS Enterprise 11.1, 11.3, and 11.5; users should upgrade to the latest long-term support release.

Affected products

  • Esri Portal for ArcGIS 11.5 and prior
  • Esri ArcGIS Enterprise 11.1, 11.3, 11.5
  • Esri ArcGIS Web App Builder developer edition

Timeline

  • 2026-08-21: disclosed

References

Related threats