Skip to content
EsriCVE-2026-9181

Esri ArcGIS Server: path traversal

Critical9.8CVE-2026-9181 · Published Jul 6, 2026 · updated Jul 8, 2026

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

Esri advisory

Affected versions

PackageAffectedFixed in
ArcGIS Server
Product
<= 12.0No fix yet
Details and references

More Esri advisories

All Esri
Advisory
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: weak password recovery
High8.1Jul 7
Esri Portal for ArcGIS: missing authentication
Critical9.8Jul 7
Esri ArcGIS Server: arbitrary file upload
Critical9.8Jul 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.