SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13019

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes are vulnerable due to a missing authentication mechanism for critical functions, enabling remote, unauthenticated attackers to exploit an unprotected API. This vulnerability poses a significant risk, as it could lead to unauthorized access and potential data breaches. Organizations using these affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-13019
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%
Windows Linux Kubernetes

Original NVD Description

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

Related CVEs

Other vulnerabilities affecting the same vendor(s)