Skip to content
EsriCVE-2026-9182

Esri ArcGIS Server: arbitrary file upload

Critical9.8CVE-2026-9182 · Published Jul 6, 2026 · updated Jul 8, 2026

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

Esri advisory

Affected versions

PackageAffectedFixed in
ArcGIS Server
Product
<= 12.0No fix yet
Details and references

More Esri advisories

All Esri
Advisory
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: cross-site scripting
Medium5.5Aug 21
Esri Portal for ArcGIS: weak password recovery
High8.1Jul 7
Esri Portal for ArcGIS: missing authentication
Critical9.8Jul 7
Esri ArcGIS Server: path traversal
Critical9.8Jul 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.