Executive brief
Esri Portal for ArcGIS is a web-based platform used to manage and share geographic information systems (GIS) data and applications within organizations. A stored cross-site scripting vulnerability in versions 11.5 and prior allows a privileged attacker to inject malicious code that executes in the browsers of other users, potentially compromising user sessions, stealing credentials, or defacing content. Organizations using ArcGIS Enterprise 11.1, 11.3, or 11.5 should apply available patches immediately.
Technical details
This is a stored (persistent) cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS affecting versions 11.5 and earlier. The vulnerability allows an authenticated, privileged user to inject malicious JavaScript that is stored in the application and executed in the browsers of other users who access the compromised content. The attack requires high-level privileges and user interaction (victim accessing the malicious content), but succeeds remotely over the network. A successful exploit enables attackers to steal session tokens, perform actions on behalf of victims, or capture sensitive information. Esri advises upgrading to the latest long-term support release or applying available security patches.
Affected products
- Esri Portal for ArcGIS 11.5 and prior
Timeline
- 2026-08-21: disclosed