Skip to content
EsriCVE-2026-69228

Esri Portal for ArcGIS: missing authentication

Medium5.3CVE-2026-69228 · Published Aug 21, 2026 · updated Sep 11, 2026

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Esri advisory

Affected versions

PackageAffectedFixed in
Portal for ArcGIS
Product
>= 11.1, <= 12.0No fix yet
Details and references

More Esri advisories

All Esri
Advisory
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium6.1Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium6.1Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium6.1Aug 21
Esri Portal for ArcGIS: cross-site scripting
Low3.8Aug 21
Esri Portal for ArcGIS: cross-site scripting
Low3.5Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.