Description
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.
Published: 2026-08-21
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Esri Portal for ArcGIS versions 12.1 and older contain a stored cross‑site scripting flaw that allows a remote, privileged attacker to inject malicious code that could execute arbitrary JavaScript in a victim’s browser. The flaw arises when user‑supplied data is stored and later rendered without proper sanitization, enabling attackers to hijack sessions, steal credentials, or perform other client‑side attacks. The impact is scoped to the victim’s browser session and can be leveraged for social‑engineering or phishing attacks.

Affected Systems

The vulnerability affects Esri Portal for ArcGIS version 12.1 and earlier, specifically ArcGIS Enterprise releases 11.1, 11.3, 11.5, 12.0, and 12.1. Users of these versions are advised to apply Esri’s patch or upgrade to the latest long‑term support release.

Risk and Exploitability

The issue carries a CVSS score of 6.1, indicating medium severity, and has no EPSS score available. While not listed in the CISA KEV catalog, the vulnerability is exploitable remotely by a privileged actor. Successful exploitation would require that the attacker can provide or influence stored content displayed to other users, typically through privileged accounts or breached credentials. The risk remains moderate, but the potential for arbitrary client‑side code execution makes timely remediation important.

Generated by OpenCVE AI on August 21, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Esri‑provided patch for Portal for ArcGIS 12.1 and earlier
  • Upgrade to the latest long‑term support release of ArcGIS Enterprise
  • Ensure stored user input is properly sanitized or enforce a Content Security Policy to limit script execution

Generated by OpenCVE AI on August 21, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.
Title stored cross site scripting issue in Esri Portal for ArcGIS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-21T20:53:36.301Z

Reserved: 2026-08-03T19:22:05.876Z

Link: CVE-2026-69236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:04.380

Modified: 2026-08-21T21:17:04.380

Link: CVE-2026-69236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')