Description
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Published: 2026-08-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication flaw that allows a remote, unauthenticated attacker to read a specific resource that should only be accessible to authenticated users. Because the flaw bypasses normal authorization checks, the attacker can obtain data from a protected endpoint. The weakness corresponds to CWE-306, reflecting a failure to enforce authentication before granting access.

Affected Systems

Esri Portal for ArcGIS is affected. Versions 12.0 and all earlier releases, including ArcGIS Enterprise 11.1, 11.3 and 11.5, are vulnerable. Users running these versions should apply the vendor patch or upgrade to the most recent long‑term support release to address the issue.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate risk. EPSS data is not available, so the current exploitation probability is unknown but the absence of a certificate does not negate the potential for exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is network‑based; an attacker can send unauthenticated requests to the exposed resource from the internet or internal network, potentially bypassing any configured authentication controls.

Generated by OpenCVE AI on August 21, 2026 at 22:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Esri‑issued patch for Esri Portal for ArcGIS 12.0 and earlier to enforce authentication on the protected resource.
  • Upgrade to the latest long‑term support release of ArcGIS Enterprise to eliminate the flaw.
  • If a patch or upgrade cannot be applied immediately, restrict external access to the vulnerable resources via firewall rules or network segmentation until remediation is completed.

Generated by OpenCVE AI on August 21, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Title missing authentication vulnerability in Esri Portal for ArcGIS
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:48:27.128Z

Reserved: 2026-08-03T19:22:01.732Z

Link: CVE-2026-69228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:03.423

Modified: 2026-08-21T21:17:03.423

Link: CVE-2026-69228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function