Esri Portal for ArcGIS
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*
- 11.4
- 11.5
- 12.0
A vulnerability in Esri Portal for ArcGIS versions 11.5 on Windows and Linux allows highly privileged users to create developer credentials that may grant excessive privileges. This incorrect privilege assignment could lead to unauthorized access or actions beyond what is intended.
Exploitation of this vulnerability could result in developer credentials being granted more privileges than expected, potentially allowing for unauthorized actions or access within the application.
Users of Esri Portal for ArcGIS 11.5 should apply the security patch released on April 13, 2026, which resets over-scoped developer credentials to their default permissions. This patch is available for both Windows and Linux. For Kubernetes customers, ArcGIS Enterprise 12.0 Update 3 should be applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.