Impact
The vulnerability is a missing authentication requirement in a critical function of Esri Portal for ArcGIS. A remote, unauthenticated attacker can invoke an unprotected API endpoint, potentially reading or modifying sensitive data. This flaw is classified as CWE-640.
Affected Systems
Affected systems are Esri Portal for ArcGIS versions 12.1 and earlier running on Windows, Linux, or Kubernetes deployments.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests a low exploitation probability currently. However, the flaw still permits a remote, unauthenticated attacker to send crafted requests to the unprotected API endpoint typical of public REST services. This vulnerability is not listed in CISA KEV catalog. The likely attack vector is publicly exposed API traffic over HTTP/HTTPS.
OpenCVE Enrichment