CVE-2026-33518
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-33518 is an incorrect privilege assignment vulnerability (CWE-266) in Esri Portal for ArcGIS 11.5 on both Windows and Linux platforms. It allows highly privileged users to create developer credentials that may grant more privileges than intended, potentially enabling privilege escalation beyond expected boundaries. The vulnerability was published on April 21, 2026, with NVD initial analysis completed on May 18, 2026. CVSS v3.1 scores differ by source: NVD assigns 7.2 (High) reflecting the high-privilege prerequisite, while the CNA (Esri) and GitHub Advisory Database assign 9.8 (Critical) based on a no-authentication-required vector (GitHub Advisory, Esri Advisory).

Technical details

The root cause is classified as CWE-266 (Incorrect Privilege Assignment), where the Portal for ArcGIS developer credential creation mechanism fails to properly constrain the privilege level of generated credentials. A highly privileged user (e.g., a portal administrator) can craft developer credentials that inherit or exceed privileges beyond what the credential type should permit. The attack vector is network-based with low complexity and requires no user interaction, though the NVD assessment notes high privileges are required as a precondition. No public proof-of-concept or detailed technical write-up describing the specific API endpoint or payload has been published (GitHub Advisory, Esri Advisory).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected Portal for ArcGIS instance. An attacker who already holds highly privileged access could generate developer credentials with unintended elevated permissions, potentially enabling unauthorized access to sensitive geospatial data, modification of portal configurations, or disruption of portal services. The scope of impact is contained to the affected component, but the ability to create over-privileged credentials could facilitate lateral movement within connected ArcGIS enterprise environments (Esri Advisory, GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the latest available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041–0.057%, placing it in a low exploitation probability percentile. Detection support exists via Tenable Nessus plugin ID 309967 (Feedly, GitHub Advisory).

Mitigation and workarounds

Esri has released a patch addressing this vulnerability, detailed in the April 2026 Security Bulletin. Organizations running Esri Portal for ArcGIS 11.5 on Windows or Linux should apply the available patch immediately. As interim measures, restrict network access to Portal instances using network segmentation, audit existing developer credentials for unexpected privilege levels, and monitor portal logs for unauthorized credential creation activity (Esri Advisory, GitHub Advisory).

Community reactions

Security news outlet SecurityOnline.info covered the vulnerability in the context of ArcGIS critical developer credential patches. BeyondMachines.net noted Esri's release of critical security patches for ArcGIS developer credential vulnerabilities. Community discussion was observed on Infosec.Exchange (Mastodon), and the vulnerability was tracked across multiple CVE aggregation platforms including VulDB and CVEFeed.io (SecurityOnline, BeyondMachines).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13020CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-13019CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-33519CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2026-33518HIGH7.2
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2025-57879MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesSep 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management