Description
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Published: 2026-08-21
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An information disclosure flaw in Esri Portal for ArcGIS allows a remote, unauthenticated attacker to reflect sensitive data in an HTTP response body. The weakness, classified as CWE‑200, undermines confidentiality by potentially exposing proprietary or personal information. In cases where the attack conditions are met, the data reflected could reveal details that the portal intended to hide from unauthenticated users.

Affected Systems

Affected systems are Esri Portal for ArcGIS versions 12.0 and earlier. The flaw exists in the portal’s handling of HTTP requests, and no specific minor releases beyond 12.0 are known to be impacted. Administrators should verify which exact version they run and note that the issue does not affect newer releases after 12.0.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity, and the EPSS score is not available, implying a lack of public exploitation data. Because the vulnerability requires difficult‑to‑reproduce conditions and is remote, the attack surface is limited to unauthenticated HTTP requests. The CVE is not listed in CISA’s KEV catalog. Nonetheless, attackers who succeed could glean sensitive data, so the risk warrants timely remediation.

Generated by OpenCVE AI on August 21, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Esri Portal for ArcGIS patch or upgrade to a version newer than 12.0.
  • Restrict network access to the portal’s HTTP endpoints to trusted IP ranges or VPNs to reduce exposure.
  • Configure the portal to return minimal error or success information to unauthenticated requests, effectively preventing data reflection.

Generated by OpenCVE AI on August 21, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Title information disclosure vulnerability in Esri Portal for ArcGIS
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:46:21.881Z

Reserved: 2026-08-03T19:22:01.731Z

Link: CVE-2026-69224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:03.150

Modified: 2026-08-21T21:17:03.150

Link: CVE-2026-69224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor