Vulnerability Details CVE-2026-33519
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-33519
-
cpe:2.3:a:esri:portal_for_arcgis:11.4
-
cpe:2.3:a:esri:portal_for_arcgis:11.5
-
cpe:2.3:a:esri:portal_for_arcgis:12.0
-
cpe:2.3:a:kubernetes:kubernetes:-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-