Portal For Arcgis Esri Portal For Arcgis

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Esri Portal For Arcgis.

By the Year

In 2026 there have been 17 vulnerabilities in Esri Portal For Arcgis with an average score of 6.3 out of ten. Last year, in 2025 Portal For Arcgis had 11 security vulnerabilities published. That is, 6 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.33.




Year Vulnerabilities Average Score
2026 17 6.33
2025 11 6.00
2024 23 5.92
2023 9 6.68
2022 20 6.56
2021 3 6.77

It may take a day or so for new Portal For Arcgis vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Esri Portal For Arcgis Security Vulnerabilities

Stored XSS in Esri Portal for ArcGIS 11.5 (privileged attacker)
CVE-2026-69233 5.5 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Esri Portal ArcGIS <11.5 Reflected XSS
CVE-2026-69234 6.1 - Medium - August 21, 2026

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.

XSS

XSS in Esri ArcGIS Portal 11.5 & prior remote code via browsers
CVE-2026-69235 6.1 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Esri Portal for ArcGIS <12.1 Stored XSS: Remote Code Exec
CVE-2026-69236 6.1 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.

XSS

Esri Portal for ArcGIS <11.3: HTML Injection in Admin API
CVE-2026-69237 3.8 - Low - August 21, 2026

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Esri Portal for ArcGIS XSS <11.5 -- Stored Cross-site Scripting
CVE-2026-69232 5.5 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Stored XSS in Esri Portal for ArcGIS <11.5
CVE-2026-69231 5.5 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Stored XSS in Esri Portal for ArcGIS <11.6 (CVE-2026-69230)
CVE-2026-69230 5.5 - Medium - August 21, 2026

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victims browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

HTML Injection in Esri Portal For ArcGIS <=12.0 (Home App)
CVE-2026-69229 5.4 - Medium - August 21, 2026

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Esri Portal for ArcGIS 12.0 Missing Auth Remote Access to Protected Resource
CVE-2026-69228 5.3 - Medium - August 21, 2026

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Missing Authentication for Critical Function

Info Disclosure in Esri Portal for ArcGIS 11.5-12.0 via HTTP Response Body
CVE-2026-69225 5.9 - Medium - August 21, 2026

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

Information Disclosure

Portal for ArcGIS HTML Injection v11.5 and prior
CVE-2026-69238 3.5 - Low - August 21, 2026

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

XSS

Esri Portal for ArcGIS <12.0 - Remote Info Disclosure in HTTP Response
CVE-2026-69224 5.9 - Medium - August 21, 2026

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

Information Disclosure

Esri Portal for ArcGIS <12.1 Unauth API Access
CVE-2026-13019 9.8 - Critical - July 07, 2026

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

Weak Password Recovery Mechanism for Forgotten Password

Weak PW Recovery in Esri Portal for ArcGIS v12.1 & earlier
CVE-2026-13020 8.1 - High - July 07, 2026

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a users account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a users password remains unchanged.

Weak Password Recovery Mechanism for Forgotten Password

Esri Portal for ArcGIS Incorrect Auth on 11.4/11.5/12.0 (Dev Creds)
CVE-2026-33519 9.8 - Critical - April 21, 2026

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Incorrect Privilege Assignment

Esri Portal for ArcGIS 11.5 Privilege Escalation via Dev Credential Abuse
CVE-2026-33518 9.8 - Critical - April 21, 2026

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

Incorrect Privilege Assignment

Reflected XSS Remote Auth Admin Exec in Esri Portal for ArcGIS <=11.4
CVE-2025-57871 4.8 - Medium - September 29, 2025

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

XSS

Unvalidated Redirect in Esri Portal for ArcGIS <=11.4 (Remote)
CVE-2025-57872 6.1 - Medium - September 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Open Redirect

Reflected XSS in Esri Portal for ArcGIS 11.4 & below via admin supplied string
CVE-2025-57873 4.8 - Medium - September 29, 2025

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

XSS

Reflected XSS in Esri Portal ArcGIS 11.4 via Admin JS
CVE-2025-57874 4.8 - Medium - September 29, 2025

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

XSS

Reflected XSS in Esri Portal for ArcGIS <=11.4 (Admin Only)
CVE-2025-57875 4.8 - Medium - September 29, 2025

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

XSS

Esri Portal for ArcGIS 11.4- Reflected XSS allows admin JS execution
CVE-2025-57877 4.8 - Medium - September 29, 2025

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

XSS

Unvalidated Redirect in Esri Portal for ArcGIS 11.4 and earlier
CVE-2025-57878 6.1 - Medium - September 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Open Redirect

Esri Portal for ArcGIS <11.4 Unvalidated Redirect Enables Phishing
CVE-2025-57879 6.1 - Medium - September 29, 2025

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Open Redirect

Esri Portal for ArcGIS 11.4 Stored XSS via Malicious File Upload
CVE-2025-57876 4.8 - Medium - September 29, 2025

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.

XSS

ArcGIS Portal 11.4 SSRF Bypass via SSRF protections (CVE-2025-4967)
CVE-2025-4967 9.1 - Critical - May 29, 2025

Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portals SSRF protections.

SSRF

Esri Portal for ArcGIS <=11.4: Hardcoded Credential Escalation
CVE-2025-2538 9.8 - Critical - March 20, 2025

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.

Use of Hard-coded Credentials

Stored XSS in Esri Portal for ArcGIS Enterprise <11.1 via Layer Showcase Config
CVE-2024-25694 4.8 - Medium - October 04, 2024

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the Layer Showcase application configuration which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.

XSS

Esri Portal for ArcGIS 11.2 and before: Unvalidated Redirect Vulnerability
CVE-2024-8148 6.1 - Medium - October 04, 2024

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Open Redirect

Reflected XSS in Esri Portal for ArcGIS v11.1/v11.2 via crafted link
CVE-2024-8149 4.6 - Medium - October 04, 2024

There is a reflected CrossSite Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may allow a remote, authenticated attacker with lowprivileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victims browser. Exploitation is limited to the same browser execution context and does not result in a change of security scope beyond the affected user session.

XSS

Esri Portal 11.1 XSS in Experience Builder Embed Widget
CVE-2024-25701 4.8 - Medium - October 04, 2024

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the Experience Builder Embed widget which when loaded could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.

XSS

Esri Portal for ArcGIS Enterprise Sites <=11.1 XSS via Config Link
CVE-2024-25702 4.8 - Medium - October 04, 2024

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in the site configuration which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high. The attack could disclose a privileged token which may result in the attacker gaining full control of the Portal.

XSS

Esri Portal Reflected XSS (<=11.1) via crafted link
CVE-2024-25691 6.1 - Medium - October 04, 2024

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.

XSS

Esri Portal for ArcGIS 11.1 and below: Reflected XSS via SelfXSS (Admin Auth)
CVE-2024-25707 4.8 - Medium - October 04, 2024

There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A user cannot be phished into clicking a link to execute code.

XSS

Esri Portal for ArcGIS XSS via Crafted Link <=10.9.1
CVE-2024-38036 5.4 - Medium - October 04, 2024

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.

XSS

Reflected XSS in Esri Portal for ArcGIS 11.1 (remote unauthenticated)
CVE-2024-38038 6.1 - Medium - October 04, 2024

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.

XSS

Esri Portal for ArcGIS <=11.0: HTML Injection via crafted link
CVE-2024-38039 5.4 - Medium - October 04, 2024

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victims browser (no stateful change made or customer data rendered).

XSS

Portal for ArcGIS <=11.2 LFI Remote URL can read internal files
CVE-2024-38040 7.5 - High - October 04, 2024

There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files.

Esri Portal for ArcGIS <11.0 Unvalidated Redirect Vulnerability (CVE-2024-38037)
CVE-2024-38037 6.1 - Medium - October 04, 2024

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

Open Redirect

Esri Portal for ArcGIS 11.1 CSRF Vulnerability
CVE-2024-25692 5.4 - Medium - April 04, 2024

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.

Session Riding

Esri Portal for ArcGIS 11.1 and Below Reflected XSS in Home App
CVE-2024-25698 6.1 - Medium - April 04, 2024

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.

XSS

Esri Portal for ArcGIS Experience Builder XSS ( 11.1) on Windows/Linux
CVE-2024-25705 5.4 - Medium - April 04, 2024

There is a crosssite scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a remote, authenticated attacker with lowprivileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victims browser. Exploitation requires basic authenticated access but does not require elevated or administrative privileges, indicating low privileges are required.

XSS

Stored XSS in Esri Portal for ArcGIS <=11.2 via item location edit
CVE-2024-25709 6.1 - Medium - April 04, 2024

There is a stored CrossSite Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could potentially execute arbitrary JavaScript code in a victims browser. Exploitation does not require any privileges and can be performed by an anonymous user.

XSS

Esri Portal for ArcGIS 11.1: Remote HTML Injection via crafted link
CVE-2024-25690 4.7 - Medium - April 04, 2024

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victims browser.

XSS

PT in Esri Portal for ArcGIS <=11.2
CVE-2024-25693 9.9 - Critical - April 04, 2024

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

Directory traversal

Portal for ArcGIS <11.2 XSS via Unsanitized Error Message Input
CVE-2024-25695 7.2 - High - April 04, 2024

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.

XSS

Portal for ArcGIS <=11.0 XSS via crafted image link in page editor
CVE-2024-25696 4.8 - Medium - April 04, 2024

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when accessing the page editor an image will render in the victims browser. The privileges required to execute this attack are high.

XSS

Portal for ArcGIS XSS: v<=11.1, attacks via bio page
CVE-2024-25697 5.4 - Medium - April 04, 2024

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.

HTML Injection in Esri Portal for ArcGIS v<=11.0 Enables Phishing
CVE-2024-25706 6.1 - Medium - April 04, 2024

There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Esri Portal For Arcgis or by Esri? Click the Watch button to subscribe.

Esri
Vendor

subscribe