CVE-2026-2812: Improper Authentication issue in ArcGIS Server
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2812?
CVE-2026-2812 is classified as a high severity vulnerability due to its potential to allow unauthorized access to an administrative endpoint in ArcGIS Server.
How do I fix CVE-2026-2812?
To remediate CVE-2026-2812, ensure that you update ArcGIS Server to version 12.1 or later, which addresses the improper authentication issue.
Which versions of ArcGIS Server are affected by CVE-2026-2812?
CVE-2026-2812 affects Esri ArcGIS Server versions up to and including 12.0.
Can CVE-2026-2812 be exploited remotely?
Yes, an unauthenticated attacker can exploit CVE-2026-2812 remotely by sending a crafted request to the exposed administrative endpoint.
What can a successful exploit of CVE-2026-2812 lead to?
Successful exploitation of CVE-2026-2812 may disrupt the operation of ArcGIS Server and compromise sensitive data.