Impact
The vulnerability allows an unauthenticated attacker to manipulate the forgotten‑password workflow in Esri Portal for ArcGIS, enabling the attacker to adopt a target user’s account. This flaw, classified as CWE‑640, defeats the intended integrity of the password recovery process and permits full control over the compromised account, potentially exposing confidential data, altering system configurations, or disrupting services. The weakness is inherent in the verification step of the password‑reset mechanism and resolves into a complete account takeover.
Affected Systems
Versions of Esri Portal for ArcGIS 12.1 and earlier, deployed on Windows, Linux, or Kubernetes, are affected. No subsequent releases are noted as vulnerable, but the description does not confirm that later versions have been patched, so administrators should confirm their system’s version.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests that exploitation examples are currently uncommon. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known active exploits exist as of the latest advisory. Based on the description, an attacker would likely trigger a publicly exposed password‑reset request and then manipulate the process without authentication or local privileges, thereby securing the target account.
OpenCVE Enrichment