PT-2026-33362 · Esri · Portal For Arcgis

Published

2026-04-16

·

Updated

2026-05-18

·

CVE-2026-33519

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Esri Portal for ArcGIS versions 11.4 through 12.0
Description An incorrect authorization issue exists where the system fails to correctly check permissions assigned to developer credentials. This flaw allows low-privilege users to generate Portal Administrator tokens by exploiting a failure in the validation of permission scopes. These unauthorized tokens can persist even after the software is patched or the user password is changed.
Recommendations Update Esri Portal for ArcGIS to a version later than 12.0. Run the Esri Credential Check Tool to identify and purge unauthorized tokens. Enforce a global policy to remove malicious credentials that may have been generated prior to patching.

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33519

Affected Products

Portal For Arcgis