Executive brief
Esri Portal for ArcGIS, a core component of ArcGIS Enterprise used to manage geospatial data and services across organizations, contains an HTML injection vulnerability. A highly privileged remote attacker could inject malicious HTML into the Portal's Home application, potentially leading to phishing, credential theft, or defacement of the web interface that administrators and users interact with daily.
Technical details
The vulnerability is an HTML injection flaw in the Portal for ArcGIS Home application that allows insertion of arbitrary HTML content. It affects versions 11.5 and prior, including ArcGIS Enterprise 11.1, 11.3, and 11.5. The attack requires a remote, highly privileged user account, limiting exposure to authenticated threat actors with significant system permissions. An attacker could inject malicious HTML to alter the application interface, redirect users, or steal credentials. Users are advised to upgrade to the latest long-term support release.
Affected products
- Esri Portal for ArcGIS 11.5 and prior
Timeline
- 2026-08-21: disclosed