← Back to CVE search

CVE-2026-9181

ArcGIS Server

Description

ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior.

CVSS 9.8EPSS 0.9440000000000001%Risk 1.06
View source
Published
2026-07-06 19:17:09
Affected versions
<=12.0
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Operating systems
Windows; Linux