← back
CVE-2026-33518

Incorrect privilege assignment in Portal for ArcGIS

CVSS 9.8 CRITICALEPSS 0.3%CWE-266
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Esri · Portal for ArcGIS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →