← Back

CVE-2026-33519

nvd nist
Published: Apr 21, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@esri.com (Secondary)

Description

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Affected (3)

1 product
Portal For Arcgis
Configuration A
3 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Esri
Version 11.4
Version 11.5
Version 12.0
Running on/withPlatform Versions
Kubernetes
Kubernetes
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

Timeline

No history available yet.