PT-2026-4787 · Esri · Arcgis Pro

Published

2026-01-26

·

Updated

2026-02-06

·

CVE-2026-1446

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Esri ArcGIS Pro versions 3.6.0 and earlier
Description A Cross Site Scripting issue exists in Esri ArcGIS Pro. A local attacker could provide malicious strings to ArcGIS Pro, which may execute when a specific dialog is opened.
Recommendations Update to version 3.6.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1446

Affected Products

Arcgis Pro