SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-69235

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Esri Portal for ArcGIS versions 11.5 and earlier are vulnerable to a stored cross-site scripting (XSS) issue, allowing remote, privileged attackers to inject malicious code that could execute in a victim's browser. This vulnerability poses a risk of arbitrary code execution, potentially compromising user data and system integrity. Organizations using affected versions, particularly those operating ArcGIS Enterprise 11.1, 11.3, and 11.5, should prioritize applying patches and upgrading to the latest long-term support release.

CVE
CVE-2026-69235
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%

Original NVD Description

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Related CVEs

Other vulnerabilities affecting the same vendor(s)