CVE-2026-33518: Incorrect privilege assignment in Portal for ArcGIS
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33518?
CVE-2026-33518 has been identified as a high severity vulnerability due to incorrect privilege assignment.
How do I fix CVE-2026-33518?
To fix CVE-2026-33518, ensure that all privileged users are properly configured and restrict the creation of developer credentials.
What software versions are affected by CVE-2026-33518?
CVE-2026-33518 affects Esri Portal for ArcGIS version 11.5 on both Windows and Linux platforms.
What type of vulnerability is CVE-2026-33518?
CVE-2026-33518 is classified as an incorrect privilege assignment vulnerability.
What are the potential risks associated with CVE-2026-33518?
The risks associated with CVE-2026-33518 include the possibility of highly privileged users gaining unintended access to elevated privileges.