Stored Cross-Site Scripting Issue in Esri Portal for ArcGIS
CVE-2026-69235

6.1MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
21 August 2026

What is CVE-2026-69235?

A stored cross-site scripting (XSS) vulnerability has been identified in Esri Portal for ArcGIS versions 11.5 and earlier, which can be leveraged by a remote, privileged attacker to inject malicious scripts. If successfully exploited, attackers can execute arbitrary code within the context of a victim's browser, potentially leading to unauthorized access or data manipulation. Users are strongly advised to upgrade to the most recent long-term support version to mitigate this risk.

Affected Version(s)

Portal for ArcGIS Windows 11.1 <= 11.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.