CVE-2026-13019
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-13019 is a missing authentication for critical function vulnerability in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. The flaw allows a remote, unauthenticated attacker to access an unprotected API endpoint without any credentials. It was published on July 7, 2026, with a patch made available the same day via Esri's June 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Esri Blog).

Technical details

The root cause is classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) per NVD, though the functional description points to a missing authentication control (CWE-306) on a critical API endpoint. The attack vector is network-based, requires no privileges, no user interaction, and low attack complexity — making it trivially automatable. An unauthenticated remote attacker can directly invoke the unprotected API over the network without bypassing any authentication layer. No public proof-of-concept code has been identified at this time (GitHub Advisory, Esri Blog).

Impact

Successful exploitation grants an unauthenticated attacker full access to a critical unprotected API, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive geospatial and organizational data, modify system configurations or stored data, and potentially disrupt service availability across all supported deployment platforms (Windows, Linux, Kubernetes). The SSVC assessment rates the technical impact as "total," indicating the potential for complete compromise of the affected Portal for ArcGIS instance (GitHub Advisory, Esri Blog).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is rated as automatable by SSVC, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 0.41%, placing it in the 33rd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in their weekly vulnerability bulletin (SB26-194) (GitHub Advisory, CISA Bulletin).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Esri Portal for ArcGIS instances running version 12.1 or earlier using tools like Shodan, Censys, or Fofa by searching for ArcGIS Portal banners or known URL patterns.
  2. Identify the unprotected API endpoint: Review Esri's public documentation or the security bulletin to identify the specific API endpoint that lacks authentication enforcement.
  3. Send unauthenticated API request: Craft and send a direct HTTP/HTTPS request to the unprotected API endpoint without supplying any authentication credentials or tokens.
  4. Achieve objective: Depending on the API's functionality, read sensitive organizational or geospatial data, modify configurations or data records, or trigger actions that disrupt service availability — all without any prior authentication (GitHub Advisory, Esri Blog).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP/HTTPS requests to Portal for ArcGIS API endpoints originating from unknown or external IP addresses, particularly without authentication headers or tokens.
  • Logs: Portal for ArcGIS access logs showing API calls to the affected endpoint from unauthenticated sessions or with missing/empty authorization fields; repeated access attempts from a single IP in a short timeframe.
  • Process/Service: Unusual data export or configuration change events recorded in Portal audit logs that are not associated with any authenticated user account.

Mitigation and workarounds

Esri has released a patch addressing this vulnerability, disclosed via the June 2026 ArcGIS Security Bulletin. Organizations should upgrade Esri Portal for ArcGIS to a version later than 12.1 as the primary remediation step. As interim mitigations, administrators should restrict network access to Portal for ArcGIS APIs using firewalls or network segmentation, limiting exposure to trusted networks only, and actively monitor access logs for unauthorized API calls to the affected endpoint (Esri Blog, GitHub Advisory).

Community reactions

Coverage of CVE-2026-13019 appeared across multiple security aggregation platforms shortly after disclosure on July 7, 2026. German technology outlet Heise.de published an English-language news article covering the ArcGIS Enterprise patch, noting the importance of the fix for geoinformation system platforms (Heise.de). Social media discussion was observed on Bluesky and Mastodon, with security researchers flagging the critical severity rating. CISA included the vulnerability in its weekly security bulletin (SB26-194), signaling broader government awareness (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13020CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-13019CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-33519CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2026-33518HIGH7.2
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2025-57879MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesSep 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management