Description
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.
Published: 2026-07-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ArcGIS Server contains a directory traversal flaw that allows an unauthenticated attacker to craft path parameters and write arbitrary files on the host. The CWE‑22 weakness can enable the attacker to modify configuration files or upload hostile code, resulting in full administrative control over the ArcGIS Server and significant compromise of confidentiality, integrity, and availability.

Affected Systems

The flaw affects Esri ArcGIS Server running on Windows and Linux, including all releases up to version 12.0 and prior. ArcGIS Enterprise deployments on Kubernetes are not impacted.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical, while the EPSS score of less than 1 % indicates that widespread exploitation has not yet been observed. The vulnerability can be triggered from any host that can reach the ArcGIS Server because no authentication is required. Although it is not listed in the CISA KEV catalog, the high severity and broad version impact warrant immediate attention.

Generated by OpenCVE AI on July 26, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Esri security patch for CVE-2026-9181 or upgrade to a version that contains the fix; official advisory and patch details are available at the Esri security bulletin.
  • Restrict network access to the ArcGIS Server by placing it behind a firewall or VPN, limiting inbound traffic to trusted networks and preventing unauthenticated hosts from reaching the web service endpoints.
  • Configure the ArcGIS Server process with the minimum required file system permissions, ensuring that it can only write to directories that are essential for normal operation and preventing accidental or malicious overwrites of critical configuration files.

Generated by OpenCVE AI on July 26, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior. Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri arcgis Server
Vendors & Products Esri
Esri arcgis Server

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior.
Title Directory Traversal in ArcGIS Server
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Esri Arcgis Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-07-08T14:44:31.974Z

Reserved: 2026-05-21T14:53:07.920Z

Link: CVE-2026-9181

cve-icon Vulnrichment

Updated: 2026-07-06T19:22:31.412Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')