Vulnerabilities
Vulnerable Software
Esri:  >> Portal For Arcgis  >> 11.5  Security Vulnerabilities
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
CVSS Score
9.8
EPSS Score
0.004
Published
2026-07-07
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-07-07
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-04-21
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-04-21


Contact Us

Shodan ® - All rights reserved