Reflected Cross Site Scripting Vulnerability in Esri Portal for ArcGIS
CVE-2026-69234
What is CVE-2026-69234?
A reflected cross site scripting vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior, potentially enabling remote, unauthenticated attackers to execute arbitrary JavaScript code in the browsers of unsuspecting users. Attackers can craft specific links that, when clicked, exploit this vulnerability, making it essential for users to update to the latest versions. Additionally, users on versions such as ArcGIS Enterprise 11.1 and 11.3 are strongly advised to adopt the latest long-term support releases to safeguard against potential threats. As ArcGIS Web App Builder developer edition is no longer supported post-assignment of this vulnerability, migration to ArcGIS Experience Builder is recommended for outstanding security.
Affected Version(s)
Portal for ArcGIS Windows 11.1 <= 11.5
