CVE-2026-33519

CRITICAL

Incorrect privilege assignment in Portal for ArcGIS

Title source: cna
STIX 2.1

Description

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-266
Status published
Products (3)
Esri/Portal for ArcGIS 11.4
Esri/Portal for ArcGIS 11.5
Esri/Portal for ArcGIS 12.0
Published Apr 21, 2026
Tracked Since Apr 22, 2026