Stored XSS Vulnerability in Esri Portal for ArcGIS by Esri
CVE-2026-69236

6.1MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
21 August 2026

What is CVE-2026-69236?

A stored cross-site scripting (XSS) vulnerability exists in Esri Portal for ArcGIS versions 12.1 and earlier. This security flaw allows a remote, privileged attacker to inject malicious JavaScript code, which can then be executed in a victim's browser. Affected users are strongly encouraged to upgrade to the latest long-term support release and apply the necessary patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

Portal for ArcGIS Windows 11.1 <= 12.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.