Stored Cross-Site Scripting Issue in Esri Portal for ArcGIS
CVE-2026-69235
6.1MEDIUM
What is CVE-2026-69235?
A stored cross-site scripting (XSS) vulnerability has been identified in Esri Portal for ArcGIS versions 11.5 and earlier, which can be leveraged by a remote, privileged attacker to inject malicious scripts. If successfully exploited, attackers can execute arbitrary code within the context of a victim's browser, potentially leading to unauthorized access or data manipulation. Users are strongly advised to upgrade to the most recent long-term support version to mitigate this risk.
Affected Version(s)
Portal for ArcGIS Windows 11.1 <= 11.5
