CVE-2026-69228: missing authentication vulnerability in Esri Portal for ArcGIS
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Esri Portal for ArcGISto a version that resolves this vulnerability.Fixed in 12.0 - Upgrade
Upgrade
Esri Portal for ArcGISto a version that resolves this vulnerability.Fixed in 11.1 - Upgrade
Upgrade
Esri Portal for ArcGISto a version that resolves this vulnerability.Fixed in 11.3 - Upgrade
Upgrade
Esri Portal for ArcGISto a version that resolves this vulnerability.Fixed in 11.5
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker does not need authentication or user interaction to exploit the issue. The affected exposure is limited to a specific resource rather than user content.
Which deployments should be prioritized for patching?
Esri specifically encourages patching ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0. The issue affects Esri Portal for ArcGIS 12.0 and earlier.
What should organizations do if they are planning remediation?
Apply the relevant patch and upgrade to the latest long-term support release, as advised by Esri. The provided information does not describe a temporary mitigation or a detection method.