CVE-2026-13019: Missing Authentication
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13019?
CVE-2026-13019 has a critical severity rating of 9.8.
What is CVE-2026-13019?
CVE-2026-13019 is a vulnerability in Esri Portal for ArcGIS that allows remote, unauthenticated access to critical functions due to missing authentication.
How do I fix CVE-2026-13019?
To fix CVE-2026-13019, upgrade Esri Portal for ArcGIS to the latest version that includes the required authentication fixes.
What systems are affected by CVE-2026-13019?
CVE-2026-13019 affects Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes.
What are the potential consequences of CVE-2026-13019?
The potential consequences of CVE-2026-13019 include unauthorized access to sensitive APIs, which can lead to data breaches and system compromise.