HTML Injection Vulnerability in Esri Portal for ArcGIS by Esri
CVE-2026-69229

5.4MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
21 August 2026

What is CVE-2026-69229?

An HTML injection vulnerability exists in Esri Portal for ArcGIS versions 12.0 and earlier, enabling a remote, authenticated attacker to inject arbitrary HTML code into the Portal for ArcGIS Home application. This could lead to various security risks, including unauthorized information disclosure or manipulation by altering the content that users access. Users working with ArcGIS Enterprise versions 11.1, 11.3, 11.5, and 12.0 are urged to apply patches and upgrade to the latest long-term support version to mitigate potential threats.

Affected Version(s)

Portal for ArcGIS Windows 11.1 <= 12.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.