CVE-2026-33519
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@esri.com (Secondary)
Description
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Affected (3)
Products: Esri: Portal For Arcgis
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4 |
| Running on/with | Platform Versions |
|---|---|
Kubernetes Kubernetes | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
References (1)
Source: psirt@esri.com
Vendor Advisory
Timeline
No history available yet.