← Back to CVE search

CVE-2026-33519

Esri Portal for ArcGIS

Description

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS 9.8EPSS 0.312%Risk 1.01
View source
Published
2026-04-21 21:16:29
Affected versions
<11.6
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Operating systems
Windows; Linux