Executive brief
Esri Portal for ArcGIS is a web-based platform used to manage geographic information systems and enterprise GIS deployments. An HTML injection vulnerability allows authenticated administrators to inject arbitrary HTML code through an administrative API, potentially compromising the integrity of the platform and enabling credential theft or malware distribution to other users.
Technical details
This is an HTML injection (also known as stored XSS precursor) vulnerability in the administrative API of Esri Portal for ArcGIS versions 11.3 and prior. The vulnerability requires administrative privileges to exploit, limiting the attack surface to privileged users. An attacker with administrative access can inject arbitrary HTML into the API, which may be rendered in the context of other users' sessions, leading to credential theft, session hijacking, or malware distribution. The vulnerability has been publicly disclosed and affects ArcGIS Enterprise 11.1 and 11.3; users should upgrade to the latest long-term support release.
Affected products
- Esri Portal for ArcGIS 11.3 and prior
Timeline
- 2026-08-21: disclosed