Description
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Published: 2026-08-21
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote, unauthenticated attacker can trigger Esri Portal for ArcGIS to return sensitive information in an HTTP response body. The vulnerability allows the attacker to read data that should be protected, potentially exposing confidential configuration, credentials, or user data. The impact is purely informational, with no direct code execution or denial of service described.

Affected Systems

Esri Portal for ArcGIS versions 11.5 through 12.0 and all earlier releases are susceptible. The vulnerability was identified in the product but not within newer releases beyond 12.0.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower known exploitation likelihood. The likely attack vector is remote and unauthenticated, as the flaw is triggered by general HTTP requests to the portal. No specific conditions such as privilege escalation or special access are required beyond the ability to send a request to the vulnerable instance.

Generated by OpenCVE AI on August 21, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Esri Portal for ArcGIS to a version newer than 12.0 that contains the fix for the information disclosure flaw.
  • Configure network security controls to restrict external access to the portal’s HTTP endpoints, reducing the opportunity for unauthenticated attackers.
  • Monitor HTTP traffic and log entries for unexpected disclosure of sensitive data, ensuring that any remaining exposure is detected promptly.

Generated by OpenCVE AI on August 21, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Title information disclosure vulnerability in Esri Portal for ArcGIS
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:46:39.386Z

Reserved: 2026-08-03T19:22:01.731Z

Link: CVE-2026-69225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:03.300

Modified: 2026-08-21T21:17:03.300

Link: CVE-2026-69225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor