Reflected Cross Site Scripting Vulnerability in Esri Portal for ArcGIS
CVE-2026-69234

6.1MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
21 August 2026

What is CVE-2026-69234?

A reflected cross site scripting vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior, potentially enabling remote, unauthenticated attackers to execute arbitrary JavaScript code in the browsers of unsuspecting users. Attackers can craft specific links that, when clicked, exploit this vulnerability, making it essential for users to update to the latest versions. Additionally, users on versions such as ArcGIS Enterprise 11.1 and 11.3 are strongly advised to adopt the latest long-term support releases to safeguard against potential threats. As ArcGIS Web App Builder developer edition is no longer supported post-assignment of this vulnerability, migration to ArcGIS Experience Builder is recommended for outstanding security.

Affected Version(s)

Portal for ArcGIS Windows 11.1 <= 11.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.