Stored XSS Vulnerability in Esri Portal for ArcGIS by Esri
CVE-2026-69236
6.1MEDIUM
What is CVE-2026-69236?
A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 12.1 and earlier. This security flaw allows a remote, privileged attacker to inject malicious JavaScript code, which can then be executed in a victim's browser. Affected users are strongly encouraged to upgrade to the latest long-term support release and apply the necessary patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Portal for ArcGIS Windows 11.1 <= 12.1
