Junglewise Threat Intelligence

CVE-2026-9181: Esri ArcGIS Server directory traversal

CVE-2026-9181 · Severity: critical · CVSS 9.8 · Published 2026-07-06

Technologies: Esri ArcGIS Server. Vendors: Esri.

Executive brief

ArcGIS Server, a platform used for sharing geographic information and maps, contains a critical security flaw. An unauthorized person can remotely access sensitive files on the server by sending specially crafted web requests. This could lead to the theft of confidential data or system configuration files, potentially compromising the entire mapping infrastructure.

Technical details

A directory traversal vulnerability (CWE-22) exists in Esri ArcGIS Server due to improper limitation of pathname parameters. An unauthenticated remote attacker can exploit this by sending specially crafted path parameters in network requests to the server. Successful exploitation allows the attacker to bypass directory restrictions and read sensitive files stored on the underlying Windows or Linux file system. The vulnerability affects all versions of ArcGIS Server up to and including version 12.0. Users are advised to refer to the Esri May 2026 Security Bulletin for patching information.

Affected products

  • Esri ArcGIS Server 12.0 and prior

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References

Related threats