Junglewise Threat Intelligence

CVE-2026-9182: Esri ArcGIS Server unrestricted file upload

CVE-2026-9182 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Esri ArcGIS Server. Vendors: Esri.

Executive brief

ArcGIS Server, a platform used for sharing geographic information and maps, contains a security flaw that allows unauthorized users to upload files to the system. An attacker could exploit this to place unauthorized files on the server, potentially leading to data integrity issues or further system compromise. Organizations using affected versions should apply the security updates provided by Esri to prevent unauthorized file modifications.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in ArcGIS Server through version 12.0. The flaw is located in an affected endpoint that fails to properly validate or restrict the types of files being uploaded. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the endpoint, resulting in arbitrary file upload to the server. While the provided CVSS score suggests limited impact (Integrity: Low), such vulnerabilities often serve as a precursor to remote code execution if the uploaded files can be accessed and executed by the web server. The vulnerability affects both Windows and Linux deployments.

Affected products

  • Esri ArcGIS Server <= 12.0

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References

Related threats