CVE-2026-69224: information disclosure vulnerability in Esri Portal for ArcGIS
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker may be able to exploit it. The vulnerable condition is described as difficult to reproduce, which indicates a high attack complexity.
What is the potential impact?
Sensitive information may be reflected in an HTTP response body. The available severity data indicates confidentiality impact only; integrity and availability impacts are not identified.
Which deployments are affected?
Esri Portal for ArcGIS version 12.0 and earlier is affected. The provided information does not identify any configuration prerequisite or unaffected configuration.