CVE-2026-2813
ArcGIS Server vulnerability analysis and mitigation

Overview

CVE-2026-2813 is an open redirect vulnerability (CWE-601) in Esri ArcGIS Server affecting version 11.5, stemming from an input validation weakness in the login redirection workflow. An authenticated attacker can send a specially crafted request to redirect a user's browser to an unintended, untrusted external site during the authentication process. The vulnerability is confined to client-side navigation logic and carries no server-side compromise potential. It was published on May 20, 2026, with a CVSS v3.1 base score of 4.1 (Medium) per NVD, or 4.7 (Moderate) per Esri's own scoring (GitHub Advisory, Esri Bulletin).

Technical details

The root cause is insufficient input validation of redirect URL parameters within ArcGIS Server's login redirection workflow, classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect). An authenticated attacker crafts a malicious request that manipulates the redirect destination used during authentication, causing the application to forward the user's browser to an attacker-controlled or otherwise untrusted site. Exploitation requires user interaction (the victim must follow the redirect) and low-level privileges (authentication is required). The vulnerability is strictly limited to client-side navigation logic and does not enable server-side code execution or cross-component impact (GitHub Advisory, Esri Bulletin).

Impact

Successful exploitation results in a limited confidentiality impact: a victim user may be redirected to a malicious or phishing site during the ArcGIS Server login process, potentially exposing credentials or other sensitive information if they interact with the fraudulent page. There is no integrity or availability impact, no server-side compromise, and no possibility of lateral movement or cross-component exploitation. The scope is changed (affecting the user's browser context beyond the ArcGIS Server security boundary), but the overall impact remains low (GitHub Advisory, Esri Bulletin).

Exploitation steps

  1. Reconnaissance: Identify ArcGIS Server 11.5 instances exposed to the network, particularly their login/authentication endpoints.
  2. Craft malicious URL: Construct a login URL that includes a manipulated redirect parameter pointing to an attacker-controlled site (e.g., https://target-arcgis-server/login?redirect=https://malicious.example.com).
  3. Deliver to victim: Send the crafted URL to an authenticated or soon-to-authenticate ArcGIS Server user via phishing email, social engineering, or embedded link.
  4. User interaction: The victim clicks the link and authenticates (or is already authenticated); the application processes the redirect parameter without adequate validation and forwards the browser to the untrusted site.
  5. Credential/data harvesting: The attacker's site mimics a legitimate page to capture credentials or session tokens entered by the victim (GitHub Advisory, Esri Bulletin).

Indicators of compromise

  • Network: HTTP requests to ArcGIS Server login endpoints containing redirect parameters pointing to external or unexpected domains (e.g., ?redirect=https://external-domain.com).
  • Logs: ArcGIS Server access logs showing login requests with unusual or external redirect parameter values; user sessions followed by immediate navigation to non-Esri/non-organizational domains.
  • User Reports: Users reporting unexpected redirects to unfamiliar sites after attempting to log in to ArcGIS Server.

Mitigation and workarounds

Esri has released a patch addressing this vulnerability; administrators should update ArcGIS Server to a version beyond 11.5 as detailed in the April 2026 Security Bulletin (Esri Bulletin). As interim mitigations, implement server-side URL validation and allowlisting for redirect destinations in authentication flows, and consider deploying Content Security Policy (CSP) headers to restrict redirect targets. User awareness training to verify URLs before entering credentials can reduce phishing risk from this class of vulnerability.

Additional resources


SourceThis report was generated using AI

Related ArcGIS Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9182CRITICAL9.8
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2026-9181HIGH7.5
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2025-67711MEDIUM6.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoDec 31, 2025
CVE-2026-2812MEDIUM5.3
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026
CVE-2026-2813MEDIUM4.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management