
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33519 is an incorrect authorization vulnerability in Esri Portal for ArcGIS that fails to correctly check permissions assigned to developer credentials, allowing unauthenticated remote attackers to bypass authorization controls. It affects Portal for ArcGIS versions 11.4, 11.5, and 12.0 on Windows, Linux, and Kubernetes deployments. The vulnerability was published on April 21, 2026, with NVD initial analysis completed on May 18, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by Esri (Environmental Systems Research Institute, Inc.) (GitHub Advisory, Esri Advisory).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment), where the application incorrectly assigns or validates privileges associated with developer credentials, creating an unintended sphere of control for unauthenticated actors (GitHub Advisory). An attacker can exploit this flaw remotely over the network with low attack complexity, requiring no privileges and no user interaction, by leveraging improperly validated developer credentials to bypass authorization checks on Portal for ArcGIS APIs or administrative interfaces. The vulnerability affects all three major deployment platforms — Windows, Linux, and Kubernetes — broadening the attack surface across on-premises and cloud-native environments (Esri Advisory). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of affected Portal for ArcGIS instances. An unauthenticated remote attacker could gain unauthorized access to sensitive geospatial data and user information, modify system configurations or hosted content, and potentially disrupt service availability across all affected deployment environments. Given that Portal for ArcGIS is commonly used in government, defense, and critical infrastructure contexts, unauthorized access could expose sensitive mapping data, organizational assets, and internal network resources, with potential for lateral movement within enterprise environments (Esri Advisory, GitHub Advisory).
As of the time of reporting, there is no known public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.043–0.064%, placing it in the lower percentiles for near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection support is available via Tenable Nessus plugin ID 309966 (Tenable).
Esri released patches for this vulnerability on April 21, 2026; organizations should apply the available security updates to Portal for ArcGIS versions 11.4, 11.5, and 12.0 immediately across all affected platforms (Windows, Linux, and Kubernetes) (Esri Advisory, GitHub Advisory). As interim mitigations, administrators should implement network-level access controls (e.g., firewall rules, reverse proxy restrictions) to limit access to Portal for ArcGIS administrative interfaces and APIs to trusted IP ranges only. Additionally, organizations should audit and review all developer credential permissions and access logs for any suspicious or anomalous activity, and revoke or rotate credentials where appropriate.
The vulnerability received coverage from security news outlets including SecurityOnline and BeyondMachines shortly after disclosure, highlighting the critical severity and the risk posed by improperly scoped developer credentials (SecurityOnline, BeyondMachines). A Reddit discussion in the r/SysAdminBlogs community raised concerns about over-scoped developer credentials in ArcGIS deployments, reflecting broader community awareness of the issue. Tenable published a Nessus detection plugin (ID 309966) to support identification of vulnerable systems (Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."