
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13020 is a Weak Password Recovery Mechanism for Forgotten Password vulnerability (CWE-640) in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can manipulate the password recovery mechanism to assume ownership of any user account, including administrative accounts. The vulnerability was published on July 7, 2026, with a patch referenced in Esri's June 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, or 8.1 (High) per the GitHub Advisory Database and Esri's own scoring (GitHub Advisory, Esri Blog).
The root cause is classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password), meaning the product's mechanism for recovering or changing passwords without knowledge of the original credential is insufficiently secure and can be manipulated by an attacker. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges, making it exploitable remotely by any unauthenticated party. The vulnerability is specifically tied to the self-service password recovery flow in Portal for ArcGIS when no email server is configured with ArcGIS Enterprise — Esri's advisory notes that configuring an email server is a key mitigation step. No public proof-of-concept code has been identified at this time (GitHub Advisory, Esri Blog).
Successful exploitation allows an unauthenticated remote attacker to fully assume ownership of any Portal for ArcGIS user account, including administrative accounts, resulting in high confidentiality, integrity, and availability impact. An attacker who takes over an administrative account gains unrestricted access to all geospatial data, configurations, and resources hosted on the Portal, with potential for lateral movement within connected ArcGIS Enterprise environments. The SSVC assessment notes the technical impact is "total," reflecting the complete compromise potential of this vulnerability (GitHub Advisory, Esri Blog).
No public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.225%, placing it in the 14th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" currently and automatable as "no," suggesting some complexity in practical exploitation despite the low attack complexity rating. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time, though CISA referenced it in a vulnerability bulletin (SB26-194) (CISA Bulletin).
Esri recommends upgrading Esri Portal for ArcGIS to a version later than 12.1, as addressed in the June 2026 ArcGIS Security Bulletin (Esri Blog). As a critical workaround, ArcGIS Administrators should configure an email server with ArcGIS Enterprise to enable secure, email-based self-service password recovery, which mitigates the weak recovery mechanism. Additionally, administrators should implement multi-factor authentication where available, enforce strict controls on administrative account access, and monitor for unauthorized account takeovers or suspicious password recovery activity. Note that the administrator's ability to manually reset user passwords is unaffected by this vulnerability.
Heise (a German technology news outlet) covered the vulnerability in an article titled "ArcGIS Enterprise: Important patch secures geoinformation system platform," highlighting the significance of the patch for enterprise GIS users (Heise). CISA included the vulnerability in its weekly vulnerability bulletin SB26-194, signaling awareness at the federal level (CISA Bulletin). Social media activity was limited, with a brief mention on Bluesky via an automated CVE tracking account. No significant researcher commentary or broader community debate has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."