Description
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Published: 2026-07-07
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to manipulate the forgotten‑password workflow in Esri Portal for ArcGIS, enabling the attacker to adopt a target user’s account. This flaw, classified as CWE‑640, defeats the intended integrity of the password recovery process and permits full control over the compromised account, potentially exposing confidential data, altering system configurations, or disrupting services. The weakness is inherent in the verification step of the password‑reset mechanism and resolves into a complete account takeover.

Affected Systems

Versions of Esri Portal for ArcGIS 12.1 and earlier, deployed on Windows, Linux, or Kubernetes, are affected. No subsequent releases are noted as vulnerable, but the description does not confirm that later versions have been patched, so administrators should confirm their system’s version.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests that exploitation examples are currently uncommon. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known active exploits exist as of the latest advisory. Based on the description, an attacker would likely trigger a publicly exposed password‑reset request and then manipulate the process without authentication or local privileges, thereby securing the target account.

Generated by OpenCVE AI on July 26, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure a properly set up email server in ArcGIS Enterprise to enable secure self‑service password recovery and thereby eliminate the insecure password‑reset flow.
  • If a patch or newer version of Esri Portal for ArcGIS is available, upgrade promptly; newer releases are not listed as vulnerable.
  • If an upgrade or email server setup is not feasible, disable or heavily restrict the insecure password‑reset functionality and monitor system logs for suspicious reset activity.

Generated by OpenCVE AI on July 26, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Tue, 07 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Title Weak Password Recovery Mechanism in Portal for ArcGIS
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-07-08T03:56:45.810Z

Reserved: 2026-06-23T16:51:44.189Z

Link: CVE-2026-13020

cve-icon Vulnrichment

Updated: 2026-07-07T17:07:56.374Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password