
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13019 is a missing authentication for critical function vulnerability in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. The flaw allows a remote, unauthenticated attacker to access an unprotected API endpoint without any credentials. It was published on July 7, 2026, with a patch made available the same day via Esri's June 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Esri Blog).
The root cause is classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) per NVD, though the functional description points to a missing authentication control (CWE-306) on a critical API endpoint. The attack vector is network-based, requires no privileges, no user interaction, and low attack complexity — making it trivially automatable. An unauthenticated remote attacker can directly invoke the unprotected API over the network without bypassing any authentication layer. No public proof-of-concept code has been identified at this time (GitHub Advisory, Esri Blog).
Successful exploitation grants an unauthenticated attacker full access to a critical unprotected API, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive geospatial and organizational data, modify system configurations or stored data, and potentially disrupt service availability across all supported deployment platforms (Windows, Linux, Kubernetes). The SSVC assessment rates the technical impact as "total," indicating the potential for complete compromise of the affected Portal for ArcGIS instance (GitHub Advisory, Esri Blog).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is rated as automatable by SSVC, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 0.41%, placing it in the 33rd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in their weekly vulnerability bulletin (SB26-194) (GitHub Advisory, CISA Bulletin).
Esri has released a patch addressing this vulnerability, disclosed via the June 2026 ArcGIS Security Bulletin. Organizations should upgrade Esri Portal for ArcGIS to a version later than 12.1 as the primary remediation step. As interim mitigations, administrators should restrict network access to Portal for ArcGIS APIs using firewalls or network segmentation, limiting exposure to trusted networks only, and actively monitor access logs for unauthorized API calls to the affected endpoint (Esri Blog, GitHub Advisory).
Coverage of CVE-2026-13019 appeared across multiple security aggregation platforms shortly after disclosure on July 7, 2026. German technology outlet Heise.de published an English-language news article covering the ArcGIS Enterprise patch, noting the importance of the fix for geoinformation system platforms (Heise.de). Social media discussion was observed on Bluesky and Mastodon, with security researchers flagging the critical severity rating. CISA included the vulnerability in its weekly security bulletin (SB26-194), signaling broader government awareness (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."