← Vulnerability feed

Vulnerability record · CVE-2026-69224 · published 21 August 2026

CVE-2026-69224: Esri portal for arcgis information exposure vulnerability

Esri · Portal For Arcgis

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

7.5 CVSS 3.1 High EPSS 0.46% · top 62.9% CWE-200 · Information exposure
7.5CVSS 3.1 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
11 Sep 2026Last modified by NVD

Description

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-69224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-25693Esri portal for arcgis path traversal vulnerabilityThere is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse …EPSS 1.3%9.8CVE-2026-13019Esri portal for arcgis weak password recovery vulnerabilityEsri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability a…EPSS 0.75%9.8CVE-2026-13020Esri portal for arcgis weak password recovery vulnerabilityA Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes…EPSS 0.47%9.8CVE-2026-33519Esri portal for arcgis vulnerabilityAn incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…EPSS 0.48%9.8CVE-2025-2538Esri portal for arcgis hard-coded credentials vulnerabilityA hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remo…EPSS 0.55%9.6CVE-2022-38193Esri portal for arcgis code injection vulnerabilityThere is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass…EPSS 0.89%9.1CVE-2025-4967Esri portal for arcgis server-side request forgery (ssrf) vulnerabilityEsri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.EPSS 0.49%8.8CVE-2023-25832Esri portal for arcgis cross-site request forgery vulnerabilityThere is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authoriz…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-69224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.