Description
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Published: 2026-08-21
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote, authenticated attacker can inject arbitrary HTML into the Esri Portal for ArcGIS Home application, leveraging a flaw in input handling (CWE‑79). This allows malicious or phishing content to be displayed to portal users, potentially compromising user trust and confidentiality. The injection occurs as part of the portal’s home page rendering, which all authenticated users can view.

Affected Systems

The vulnerability affects Esri’s Portal for ArcGIS version 12.0 and earlier. Customers using ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0 are a high‑risk target group because the affected portal versions are included with these Enterprise releases.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, suggesting current exploitation rates are low. The attacker must first authenticate to the portal, after which arbitrary HTML can be submitted and rendered, giving the attacker a persisting local vector that might be used for social engineering or content manipulation.

Generated by OpenCVE AI on August 21, 2026 at 22:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Esri‑provided security patch that updates Portal for ArcGIS past version 12.0.
  • Upgrade to the latest long‑term support release of ArcGIS Enterprise, which includes a patched portal.
  • Restrict or sanitize any HTML‑accepting settings in the portal configuration to enforce proper input validation.

Generated by OpenCVE AI on August 21, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Title HTML injection vulnerability in Esri Portal for ArcGIS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:48:46.187Z

Reserved: 2026-08-03T19:22:01.732Z

Link: CVE-2026-69229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:03.547

Modified: 2026-08-21T21:17:03.547

Link: CVE-2026-69229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')