Description
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.
Published: 2026-08-21
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A reflected cross‑site scripting flaw exists in Esri Portal for ArcGIS allowing a remote, unauthenticated attacker to craft a malicious link. When a user clicks the link, arbitrary JavaScript can run in the victim’s browser, potentially stealing session information, defacing content, or executing further malicious actions. The vulnerability does not grant code access on the server but permits client‑side exploitation under the victim’s user context.

Affected Systems

The flaw affects Esri Portal for ArcGIS versions 11.5 and all earlier releases. Specifically, ArcGIS Enterprise 11.1, 11.3, and 11.5 users must patch. Organizations that run the ArcGIS Web App Builder developer edition should discontinue use or migrate to ArcGIS Experience Builder, as the developer edition is unsupported for this CVE.

Risk and Exploitability

With a CVSS score of 6.1 the risk is moderate. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation at the time of this assessment. The attack vector is remote and requires an unauthenticated user to click a crafted URL, so success relies on social engineering or phishing. Once triggered, the incident can lead to data theft or session hijacking in the victim’s browser, but does not compromise the ArcGIS server itself.

Generated by OpenCVE AI on August 21, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all Esri Portal for ArcGIS installations running version 11.5 or earlier in your environment.
  • Apply Esri’s published security update or install the latest long‑term support release for Portal for ArcGIS.
  • If your organization uses ArcGIS Web App Builder developer edition, stop using it and migrate to ArcGIS Experience Builder as recommended by Esri.

Generated by OpenCVE AI on August 21, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.
Title reflected cross site scripting vulnerability in Esri Portal for ArcGIS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:54:00.726Z

Reserved: 2026-08-03T19:22:05.876Z

Link: CVE-2026-69234

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:04.140

Modified: 2026-08-21T21:17:04.140

Link: CVE-2026-69234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')