Portal for ArcGIS vulnerability

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

Published 21 Aug 2026Updated 11 Sep 20261 sources
CVSS 5.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.