CVE-2026-33519
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-33519 is an incorrect authorization vulnerability in Esri Portal for ArcGIS that fails to correctly check permissions assigned to developer credentials, allowing unauthenticated remote attackers to bypass authorization controls. It affects Portal for ArcGIS versions 11.4, 11.5, and 12.0 on Windows, Linux, and Kubernetes deployments. The vulnerability was published on April 21, 2026, with NVD initial analysis completed on May 18, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by Esri (Environmental Systems Research Institute, Inc.) (GitHub Advisory, Esri Advisory).

Technical details

The root cause is classified as CWE-266 (Incorrect Privilege Assignment), where the application incorrectly assigns or validates privileges associated with developer credentials, creating an unintended sphere of control for unauthenticated actors (GitHub Advisory). An attacker can exploit this flaw remotely over the network with low attack complexity, requiring no privileges and no user interaction, by leveraging improperly validated developer credentials to bypass authorization checks on Portal for ArcGIS APIs or administrative interfaces. The vulnerability affects all three major deployment platforms — Windows, Linux, and Kubernetes — broadening the attack surface across on-premises and cloud-native environments (Esri Advisory). No public proof-of-concept exploit code has been identified at this time.

Impact

Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of affected Portal for ArcGIS instances. An unauthenticated remote attacker could gain unauthorized access to sensitive geospatial data and user information, modify system configurations or hosted content, and potentially disrupt service availability across all affected deployment environments. Given that Portal for ArcGIS is commonly used in government, defense, and critical infrastructure contexts, unauthorized access could expose sensitive mapping data, organizational assets, and internal network resources, with potential for lateral movement within enterprise environments (Esri Advisory, GitHub Advisory).

Exploitability

As of the time of reporting, there is no known public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.043–0.064%, placing it in the lower percentiles for near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection support is available via Tenable Nessus plugin ID 309966 (Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Esri Portal for ArcGIS instances running versions 11.4, 11.5, or 12.0 using tools such as Shodan or Censys, targeting exposed REST API endpoints or administrative web interfaces.
  2. Identify developer credential endpoints: Locate Portal for ArcGIS API endpoints that accept or process developer credentials (e.g., OAuth tokens or API keys), which are subject to the flawed permission-checking logic.
  3. Craft malicious request: Send a crafted network request using developer credentials (or credential artifacts) that exploits the incorrect privilege assignment flaw, bypassing the expected authorization checks.
  4. Achieve unauthorized access: Leverage the bypassed authorization to access restricted Portal resources, administrative functions, or sensitive geospatial data without valid elevated permissions.
  5. Post-exploitation: Exfiltrate sensitive data, modify hosted layers or configurations, create backdoor accounts, or pivot to connected enterprise systems (Esri Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous API requests to Portal for ArcGIS REST endpoints from unauthenticated or low-privilege sources; unusual outbound connections from the Portal server to unknown external IPs.
  • Logs: Portal access logs showing requests to administrative or developer API endpoints with developer credentials accessing resources beyond their assigned permission scope; repeated authorization-related errors or unexpected successful access events in Portal logs.
  • File System: Unexpected changes to Portal configuration files, hosted service definitions, or web application content directories.
  • Process/Behavior: Unusual administrative actions (e.g., new user creation, permission changes, data exports) performed by developer-level credential accounts; unexpected service restarts or configuration modifications on the Portal host.

Mitigation and workarounds

Esri released patches for this vulnerability on April 21, 2026; organizations should apply the available security updates to Portal for ArcGIS versions 11.4, 11.5, and 12.0 immediately across all affected platforms (Windows, Linux, and Kubernetes) (Esri Advisory, GitHub Advisory). As interim mitigations, administrators should implement network-level access controls (e.g., firewall rules, reverse proxy restrictions) to limit access to Portal for ArcGIS administrative interfaces and APIs to trusted IP ranges only. Additionally, organizations should audit and review all developer credential permissions and access logs for any suspicious or anomalous activity, and revoke or rotate credentials where appropriate.

Community reactions

The vulnerability received coverage from security news outlets including SecurityOnline and BeyondMachines shortly after disclosure, highlighting the critical severity and the risk posed by improperly scoped developer credentials (SecurityOnline, BeyondMachines). A Reddit discussion in the r/SysAdminBlogs community raised concerns about over-scoped developer credentials in ArcGIS deployments, reflecting broader community awareness of the issue. Tenable published a Nessus detection plugin (ID 309966) to support identification of vulnerable systems (Tenable).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13020CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-13019CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesJul 07, 2026
CVE-2026-33519CRITICAL9.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2026-33518HIGH7.2
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoApr 21, 2026
CVE-2025-57879MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoYesSep 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management