Missing Authentication Vulnerability in Esri Portal for ArcGIS
CVE-2026-69228
5.3MEDIUM
What is CVE-2026-69228?
A missing authentication vulnerability exists in Esri Portal for ArcGIS versions up to 12.0. This issue allows remote, unauthenticated attackers to gain access to specific resources intended solely for authenticated users. It is essential for users of ArcGIS Enterprise versions 11.1, 11.3, 11.5, and 12.0 to apply the necessary patch to mitigate this vulnerability. Users are strongly advised to upgrade to the latest long-term support release to ensure enhanced security and protection.
Affected Version(s)
Portal for ArcGIS Windows 11.1 <= 12.0
