CVE-2026-13020
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-13020 is a Weak Password Recovery Mechanism for Forgotten Password vulnerability (CWE-640) in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can manipulate the password recovery mechanism to assume ownership of any user account, including administrative accounts. The vulnerability was published on July 7, 2026, with a patch referenced in Esri's June 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, or 8.1 (High) per the GitHub Advisory Database and Esri's own scoring (GitHub Advisory, Esri Blog).

Technical details

The root cause is classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password), meaning the product's mechanism for recovering or changing passwords without knowledge of the original credential is insufficiently secure and can be manipulated by an attacker. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges, making it exploitable remotely by any unauthenticated party. The vulnerability is specifically tied to the self-service password recovery flow in Portal for ArcGIS when no email server is configured with ArcGIS Enterprise — Esri's advisory notes that configuring an email server is a key mitigation step. No public proof-of-concept code has been identified at this time (GitHub Advisory, Esri Blog).

Impact

Successful exploitation allows an unauthenticated remote attacker to fully assume ownership of any Portal for ArcGIS user account, including administrative accounts, resulting in high confidentiality, integrity, and availability impact. An attacker who takes over an administrative account gains unrestricted access to all geospatial data, configurations, and resources hosted on the Portal, with potential for lateral movement within connected ArcGIS Enterprise environments. The SSVC assessment notes the technical impact is "total," reflecting the complete compromise potential of this vulnerability (GitHub Advisory, Esri Blog).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.225%, placing it in the 14th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" currently and automatable as "no," suggesting some complexity in practical exploitation despite the low attack complexity rating. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time, though CISA referenced it in a vulnerability bulletin (SB26-194) (CISA Bulletin).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Esri Portal for ArcGIS instances running version 12.1 or earlier using tools like Shodan or Censys, searching for ArcGIS Portal login pages or API endpoints.
  2. Identify target accounts: Enumerate valid usernames or email addresses associated with the Portal, potentially via public-facing directory features or error message differences in the password recovery flow.
  3. Trigger password recovery: Initiate the forgotten password recovery mechanism for a target account (e.g., an administrator account) via the Portal's self-service recovery interface.
  4. Manipulate the recovery mechanism: Exploit the weakness in the recovery flow — such as predictable tokens, insufficient validation, or lack of email-based verification — to intercept or forge the recovery process and gain control of the account.
  5. Account takeover: Complete the password reset to assume ownership of the target account, gaining full access to Portal resources, data, and administrative functions (GitHub Advisory, Esri Blog).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Portal for ArcGIS password recovery endpoints from unexpected source IPs; high volume of password reset requests targeting multiple accounts in a short timeframe.
  • Logs: Portal access logs showing password recovery requests for administrative or high-privilege accounts from unfamiliar IP addresses or geographic locations; successful password changes not initiated by the account owner or an administrator.
  • Authentication: Unexpected logins to Portal accounts from new devices, IP addresses, or at unusual times following a password recovery event; administrator accounts showing login activity inconsistent with normal usage patterns.
  • Application: Audit logs in ArcGIS Enterprise showing account ownership changes or privilege escalations not authorized by known administrators.

Mitigation and workarounds

Esri recommends upgrading Esri Portal for ArcGIS to a version later than 12.1, as addressed in the June 2026 ArcGIS Security Bulletin (Esri Blog). As a critical workaround, ArcGIS Administrators should configure an email server with ArcGIS Enterprise to enable secure, email-based self-service password recovery, which mitigates the weak recovery mechanism. Additionally, administrators should implement multi-factor authentication where available, enforce strict controls on administrative account access, and monitor for unauthorized account takeovers or suspicious password recovery activity. Note that the administrator's ability to manually reset user passwords is unaffected by this vulnerability.

Community reactions

Heise (a German technology news outlet) covered the vulnerability in an article titled "ArcGIS Enterprise: Important patch secures geoinformation system platform," highlighting the significance of the patch for enterprise GIS users (Heise). CISA included the vulnerability in its weekly vulnerability bulletin SB26-194, signaling awareness at the federal level (CISA Bulletin). Social media activity was limited, with a brief mention on Bluesky via an automated CVE tracking account. No significant researcher commentary or broader community debate has been observed.

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13020CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-13019CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-33519CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2026-33518HIGH7.2
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2025-57879MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesSep 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management