5.3
CVE-2026-69228
- EPSS 0.34%
- Veröffentlicht 21.08.2026 21:17:03
- Zuletzt bearbeitet 11.09.2026 17:51:42
- Erkennungen
missing authentication vulnerability in Esri Portal for ArcGIS
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Esri ≫ Portal For Arcgis Version < 11.1
Esri ≫ Portal For Arcgis Version 11.1 Update -
Esri ≫ Portal For Arcgis Version 11.1 Update security_2024_update1
Esri ≫ Portal For Arcgis Version 11.1 Update security_2024_update2
Esri ≫ Portal For Arcgis Version 11.1 Update security_2025_update1
Esri ≫ Portal For Arcgis Version 11.1 Update security_2025_update2
Esri ≫ Portal For Arcgis Version 11.1 Update security_2025_update3
Esri ≫ Portal For Arcgis Version 11.1 Update security_2026_update2
Esri ≫ Portal For Arcgis Version 11.2
Esri ≫ Portal For Arcgis Version 11.3 Update -
Esri ≫ Portal For Arcgis Version 11.3 Update security_2025_update1
Esri ≫ Portal For Arcgis Version 11.3 Update security_2025_update2
Esri ≫ Portal For Arcgis Version 11.3 Update security_2025_update3
Esri ≫ Portal For Arcgis Version 11.3 Update security_2026_update2
Esri ≫ Portal For Arcgis Version 11.4
Esri ≫ Portal For Arcgis Version 11.5 Update -
Esri ≫ Portal For Arcgis Version 11.5 Update security_2026_update1
Esri ≫ Portal For Arcgis Version 11.5 Update security_2026_update2
Esri ≫ Portal For Arcgis Version 12.0 Update -
Esri ≫ Portal For Arcgis Version 12.0 Update security_2026_update1
Esri ≫ Portal For Arcgis Version 12.0 Update security_2026_update2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.274 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@esri.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin