PT-2026-33362 · Esri · Portal For Arcgis
Published
2026-04-16
·
Updated
2026-05-18
·
CVE-2026-33519
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Esri Portal for ArcGIS versions 11.4 through 12.0
Description
An incorrect authorization issue exists where the system fails to correctly check permissions assigned to developer credentials. This flaw allows low-privilege users to generate Portal Administrator tokens by exploiting a failure in the validation of permission scopes. These unauthorized tokens can persist even after the software is patched or the user password is changed.
Recommendations
Update Esri Portal for ArcGIS to a version later than 12.0.
Run the Esri Credential Check Tool to identify and purge unauthorized tokens.
Enforce a global policy to remove malicious credentials that may have been generated prior to patching.
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Portal For Arcgis