Description
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication requirement in a critical function of Esri Portal for ArcGIS. A remote, unauthenticated attacker can invoke an unprotected API endpoint, potentially reading or modifying sensitive data. This flaw is classified as CWE-640.

Affected Systems

Affected systems are Esri Portal for ArcGIS versions 12.1 and earlier running on Windows, Linux, or Kubernetes deployments.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests a low exploitation probability currently. However, the flaw still permits a remote, unauthenticated attacker to send crafted requests to the unprotected API endpoint typical of public REST services. This vulnerability is not listed in CISA KEV catalog. The likely attack vector is publicly exposed API traffic over HTTP/HTTPS.

Generated by OpenCVE AI on July 26, 2026 at 19:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Esri Portal for ArcGIS to a supported version newer than 12.1, or apply the vendor‑supplied update that addresses the missing authentication flaw.
  • Reconfigure or harden any exposed API endpoints by enforcing authentication, or limit network access to the portal through firewall or network segmentation.
  • Enable comprehensive logging for API calls and regularly review audit logs for suspicious activity.

Generated by OpenCVE AI on July 26, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
Title Missing Authentication
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-07-08T03:56:44.996Z

Reserved: 2026-06-23T16:51:42.540Z

Link: CVE-2026-13019

cve-icon Vulnrichment

Updated: 2026-07-07T17:02:01.896Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password