SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-69228

MEDIUM · CVSS 5.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier allows remote, unauthenticated attackers to access restricted resources intended for authenticated users. This could lead to unauthorized exposure of sensitive information. Organizations using ArcGIS Enterprise versions 11.1, 11.3, 11.5, or 12.0 should prioritize patching to mitigate this risk.

CVE
CVE-2026-69228
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%

Original NVD Description

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Related CVEs

Other vulnerabilities affecting the same vendor(s)