← back
CVE-2026-33519

Incorrect privilege assignment in Portal for ArcGIS

CVSS 9.8 CRITICALEPSS 0.3%CWE-266
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Esri · Portal for ArcGIS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →