CVE-2026-33519: Incorrect privilege assignment in Portal for ArcGIS
Published Apr 21, 2026
·Updated
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Affected Software
7 affected components
Esri Portal for ArcGIS=11.4, =11.5, =12.0
All of the following
Any of the following
Esri Portal for ArcGIS=11.4
Esri Portal for ArcGIS=11.5
Esri Portal for ArcGIS=12.0
Any of the following
Kubernetes kubernetes
Linux Linux kernel
Microsoft Windows
Event History
Apr 21, 2026
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33519?
CVE-2026-33519 has a critical severity level due to the potential for unauthorized privilege escalation.
2
How do I fix CVE-2026-33519?
To fix CVE-2026-33519, update Esri Portal for ArcGIS to the latest secure versions available.
3
What products are affected by CVE-2026-33519?
CVE-2026-33519 affects Esri Portal for ArcGIS versions 11.4, 11.5, and 12.0.
4
Can CVE-2026-33519 be exploited remotely?
Yes, CVE-2026-33519 can be exploited remotely if the affected software is accessible over the network.
5
What are the potential impacts of CVE-2026-33519?
The potential impacts of CVE-2026-33519 include unauthorized access to sensitive functionalities and data due to incorrect privilege assignments.