
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69237 is an HTML injection vulnerability in Esri Portal for ArcGIS that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API endpoint. It affects Portal for ArcGIS versions 11.1 through 11.3 (on both Windows and Linux platforms); versions prior to 11.1 and later than 11.3 are listed as unaffected by default. The vulnerability was published on August 21, 2026, by Esri (Environmental Systems Research Institute, Inc.) as part of their August 2026 ArcGIS Security Bulletin. It carries a CVSS v3.1 base score of 3.8 (Low) (GitHub Advisory, Esri Blog).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), specifically manifesting as HTML injection due to insufficient sanitization of user-supplied input before it is rendered in an administrative API response (GitHub Advisory). An attacker must already possess administrative privileges and network access to the Portal for ArcGIS administrative API to exploit this flaw; no user interaction is required beyond the attacker's own authenticated session. The attack vector is network-based with low complexity, but the high privilege requirement significantly limits the attack surface. No public proof-of-concept code or detailed technical write-ups have been identified at this time (GitHub Advisory).
Successful exploitation allows an authenticated administrator to inject arbitrary HTML content into administrative API responses, potentially enabling content spoofing, phishing of other administrators interacting with the API, or manipulation of displayed information within the administrative interface. The confidentiality and integrity impacts are both rated Low, and there is no availability impact, meaning the vulnerability does not enable remote code execution, data exfiltration at scale, or service disruption (GitHub Advisory, Esri Blog). The scope is unchanged, limiting the blast radius to the affected Portal for ArcGIS component itself.
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-69237 (GitHub Advisory). The EPSS score is approximately 0.196% (roughly the 10th percentile), indicating a low probability of exploitation within the next 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The high privilege requirement (administrative access) further reduces practical exploitability.
Esri recommends that users of ArcGIS Enterprise versions 11.1 and 11.3 apply the available patch, and all users are advised to upgrade to the latest long-term support release (a version later than 11.3) (Esri Blog). As a configuration-based mitigation, organizations should restrict administrative API access to trusted internal networks and limit administrative privileges to only necessary personnel. Monitoring and auditing administrative API activity can help detect any anomalous HTML injection attempts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."