
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9182 is an unrestricted file upload vulnerability (CWE-434) in Esri ArcGIS Server affecting all versions on Windows and Linux up to and including version 12.0. An unauthenticated remote attacker can exploit this vulnerability by uploading a crafted file to an affected endpoint, potentially enabling arbitrary file upload and further attacks such as remote code execution. ArcGIS Enterprise for Kubernetes is not affected. The vulnerability was published on July 6, 2026, with a patch referenced in Esri's May 2026 ArcGIS Security Bulletin. NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database and ENISA EUVD assign a more conservative score of 5.3 (Moderate) (GitHub Advisory, Esri Blog).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning ArcGIS Server fails to adequately validate or restrict the type of files that can be uploaded to a specific endpoint. An unauthenticated attacker can send a crafted HTTP request containing a malicious file to the vulnerable endpoint over the network, with no privileges or user interaction required. Successful exploitation could allow the attacker to place arbitrary files on the server, which — depending on server configuration and file handling — could be leveraged for remote code execution or other follow-on attacks. No specific endpoint path or technical write-up has been publicly disclosed at this time (GitHub Advisory, Esri Blog).
Successful exploitation allows an unauthenticated attacker to upload arbitrary files to the ArcGIS Server host, with potential consequences ranging from web shell deployment and remote code execution to full system compromise. The vulnerability affects confidentiality, integrity, and availability of the server, and could serve as an initial foothold for lateral movement within an organization's network. All ArcGIS Server deployments on Windows and Linux at version 12.0 and below are at risk, which may include environments hosting sensitive geospatial data (GitHub Advisory, Esri Blog).
.jsp, .aspx, or script file) that, if executed by the server, would provide remote code execution capability..jsp, .aspx, .php, .py, .sh) in ArcGIS Server web directories or upload directories; newly created files with executable permissions in server directories.cmd.exe, powershell.exe, /bin/bash, curl, wget) indicating potential web shell execution.Esri has released a patch addressing this vulnerability, detailed in the May 2026 ArcGIS Security Bulletin. Organizations should upgrade ArcGIS Server to a version beyond 12.0 as the primary remediation step. As an interim workaround, restrict network access to ArcGIS Server file upload endpoints using firewall rules, network segmentation, or reverse proxy controls to limit exposure to trusted IP ranges only. Monitor server logs for anomalous upload activity while patches are being deployed (Esri Blog, GitHub Advisory).
The vulnerability was noted in a weekly threat landscape digest shortly after disclosure, indicating moderate community awareness (Hawk-Eye). CISA referenced the vulnerability in its weekly security bulletin (SB26-194), signaling government-level awareness (CISA Bulletin). No significant vendor statements beyond the Esri security bulletin or notable independent researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."