
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2813 is an open redirect vulnerability (CWE-601) in Esri ArcGIS Server affecting version 11.5, stemming from an input validation weakness in the login redirection workflow. An authenticated attacker can send a specially crafted request to redirect a user's browser to an unintended, untrusted external site during the authentication process. The vulnerability is confined to client-side navigation logic and carries no server-side compromise potential. It was published on May 20, 2026, with a CVSS v3.1 base score of 4.1 (Medium) per NVD, or 4.7 (Moderate) per Esri's own scoring (GitHub Advisory, Esri Bulletin).
The root cause is insufficient input validation of redirect URL parameters within ArcGIS Server's login redirection workflow, classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect). An authenticated attacker crafts a malicious request that manipulates the redirect destination used during authentication, causing the application to forward the user's browser to an attacker-controlled or otherwise untrusted site. Exploitation requires user interaction (the victim must follow the redirect) and low-level privileges (authentication is required). The vulnerability is strictly limited to client-side navigation logic and does not enable server-side code execution or cross-component impact (GitHub Advisory, Esri Bulletin).
Successful exploitation results in a limited confidentiality impact: a victim user may be redirected to a malicious or phishing site during the ArcGIS Server login process, potentially exposing credentials or other sensitive information if they interact with the fraudulent page. There is no integrity or availability impact, no server-side compromise, and no possibility of lateral movement or cross-component exploitation. The scope is changed (affecting the user's browser context beyond the ArcGIS Server security boundary), but the overall impact remains low (GitHub Advisory, Esri Bulletin).
https://target-arcgis-server/login?redirect=https://malicious.example.com).?redirect=https://external-domain.com).Esri has released a patch addressing this vulnerability; administrators should update ArcGIS Server to a version beyond 11.5 as detailed in the April 2026 Security Bulletin (Esri Bulletin). As interim mitigations, implement server-side URL validation and allowlisting for redirect destinations in authentication flows, and consider deploying Content Security Policy (CSP) headers to restrict redirect targets. User awareness training to verify URLs before entering credentials can reduce phishing risk from this class of vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."