Description
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Published: 2026-08-21
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious scripts into Esri Portal for ArcGIS. When a victim’s browser renders the affected content, the injected script can execute arbitrary code within the victim’s browser context. Based on the description, the likely attack vector is from a remote source that has administrative privileges within the portal, although this is not explicitly stated in the advisory and is therefore inferred.

Affected Systems

Esri Portal for ArcGIS versions 11.5 and earlier, specifically 11.1, 11.3, and 11.5, are affected. All ArcGIS Enterprise deployments up to version 11.5 should be considered vulnerable until they are patched or upgraded to the latest long‑term support release.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The vulnerability requires remote interaction with the portal but only from users possessing administrative rights. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, so the likelihood of exploitation is considered moderate. Because the advisory specifies remote, administratively privileged access as a prerequisite, that is the inferred attack vector, but no public exploits are reported.

Generated by OpenCVE AI on August 21, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest long‑term support version of Esri Portal for ArcGIS or apply the official vendor patch for versions 11.1, 11.3, and 11.5.
  • Limit administrative access to trusted personnel and regularly audit privileged accounts to reduce the attack surface.
  • Implement a web application firewall or security filter that blocks common XSS payloads and enforce a strict content‑security policy to mitigate remaining risks.

Generated by OpenCVE AI on August 21, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Title stored cross site scripting issue in Esri Portal for ArcGIS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:49:01.503Z

Reserved: 2026-08-03T19:22:01.732Z

Link: CVE-2026-69230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:03.670

Modified: 2026-08-21T21:17:03.670

Link: CVE-2026-69230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')