
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2812 is an improper authentication vulnerability (CWE-287) in Esri ArcGIS Server affecting versions 11.1 through 12.0. The flaw resides in an undocumented administrative endpoint and allows unauthenticated remote attackers to send crafted requests that disrupt the web-based browsing interface. It was published on May 20, 2026, with a patch referenced in Esri's April 2026 security bulletin. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Esri Bulletin).
The root cause is improper authentication (CWE-287) on an undocumented administrative endpoint within ArcGIS Server, meaning the server fails to adequately verify the identity of requesters before processing administrative actions. An unauthenticated attacker can exploit this by sending a specially crafted HTTP request directly to the hidden endpoint over the network, requiring no credentials, no user interaction, and no elevated privileges. The attack complexity is low, making it straightforward to attempt. No public proof-of-concept code has been identified at this time (GitHub Advisory, Esri Bulletin).
Successful exploitation results in disruption of the ArcGIS Server web-based browsing interface, representing an integrity impact on the affected service. The CVSS scoring reflects no confidentiality or availability impact, meaning attackers cannot directly exfiltrate data or fully take down the server through this vulnerability alone. However, disruption of the administrative web interface could impair administrators' ability to manage GIS services, potentially affecting downstream geospatial workflows and applications that depend on ArcGIS Server (GitHub Advisory, Esri Bulletin).
Esri has released a patch addressing this vulnerability; users should upgrade ArcGIS Server to a version newer than 12.0 as referenced in the April 2026 security bulletin (Esri Bulletin). As a network-level workaround, administrators should restrict access to ArcGIS Server administrative endpoints using firewalls or network access controls, limiting reachability to trusted IP ranges only. Additionally, organizations should audit all administrative endpoints — particularly undocumented ones — and enforce authentication requirements where possible.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."