CVE-2026-9182
ArcGIS Server vulnerability analysis and mitigation

Overview

CVE-2026-9182 is an unrestricted file upload vulnerability (CWE-434) in Esri ArcGIS Server affecting all versions on Windows and Linux up to and including version 12.0. An unauthenticated remote attacker can exploit this vulnerability by uploading a crafted file to an affected endpoint, potentially enabling arbitrary file upload and further attacks such as remote code execution. ArcGIS Enterprise for Kubernetes is not affected. The vulnerability was published on July 6, 2026, with a patch referenced in Esri's May 2026 ArcGIS Security Bulletin. NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database and ENISA EUVD assign a more conservative score of 5.3 (Moderate) (GitHub Advisory, Esri Blog).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning ArcGIS Server fails to adequately validate or restrict the type of files that can be uploaded to a specific endpoint. An unauthenticated attacker can send a crafted HTTP request containing a malicious file to the vulnerable endpoint over the network, with no privileges or user interaction required. Successful exploitation could allow the attacker to place arbitrary files on the server, which — depending on server configuration and file handling — could be leveraged for remote code execution or other follow-on attacks. No specific endpoint path or technical write-up has been publicly disclosed at this time (GitHub Advisory, Esri Blog).

Impact

Successful exploitation allows an unauthenticated attacker to upload arbitrary files to the ArcGIS Server host, with potential consequences ranging from web shell deployment and remote code execution to full system compromise. The vulnerability affects confidentiality, integrity, and availability of the server, and could serve as an initial foothold for lateral movement within an organization's network. All ArcGIS Server deployments on Windows and Linux at version 12.0 and below are at risk, which may include environments hosting sensitive geospatial data (GitHub Advisory, Esri Blog).

Exploitation steps

  1. Reconnaissance: Identify internet-facing ArcGIS Server instances running version 12.0 or earlier on Windows or Linux using tools such as Shodan, Censys, or targeted web scanning. Confirm the server is not ArcGIS Enterprise for Kubernetes, which is unaffected.
  2. Identify vulnerable endpoint: Locate the specific file upload endpoint exposed by ArcGIS Server. The exact endpoint has not been publicly disclosed, but typical ArcGIS Server REST or administrative endpoints may be candidates.
  3. Craft malicious file: Prepare a file of a dangerous type (e.g., a web shell such as a .jsp, .aspx, or script file) that, if executed by the server, would provide remote code execution capability.
  4. Upload crafted file: Send an unauthenticated HTTP POST request containing the malicious file to the vulnerable endpoint, bypassing any file type restrictions due to the lack of server-side validation.
  5. Achieve code execution: If the uploaded file is placed in a web-accessible directory and the server processes or serves it, access the file via HTTP to trigger execution, establishing a reverse shell or enabling further post-exploitation activity (GitHub Advisory, Esri Blog).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to ArcGIS Server file upload endpoints from unauthenticated or unknown source IPs; unusual outbound connections from the ArcGIS Server host to external IPs following file upload activity.
  • File System: Presence of unexpected script files (e.g., .jsp, .aspx, .php, .py, .sh) in ArcGIS Server web directories or upload directories; newly created files with executable permissions in server directories.
  • Logs: ArcGIS Server access logs showing POST requests to upload-related endpoints from unauthenticated sessions; HTTP 200 responses to requests for newly uploaded files not matching expected content types.
  • Process: Unusual child processes spawned by the ArcGIS Server Java or application process (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) indicating potential web shell execution.

Mitigation and workarounds

Esri has released a patch addressing this vulnerability, detailed in the May 2026 ArcGIS Security Bulletin. Organizations should upgrade ArcGIS Server to a version beyond 12.0 as the primary remediation step. As an interim workaround, restrict network access to ArcGIS Server file upload endpoints using firewall rules, network segmentation, or reverse proxy controls to limit exposure to trusted IP ranges only. Monitor server logs for anomalous upload activity while patches are being deployed (Esri Blog, GitHub Advisory).

Community reactions

The vulnerability was noted in a weekly threat landscape digest shortly after disclosure, indicating moderate community awareness (Hawk-Eye). CISA referenced the vulnerability in its weekly security bulletin (SB26-194), signaling government-level awareness (CISA Bulletin). No significant vendor statements beyond the Esri security bulletin or notable independent researcher commentary have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related ArcGIS Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9182CRITICAL9.8
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2026-9181HIGH7.5
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoJul 06, 2026
CVE-2025-67711MEDIUM6.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoDec 31, 2025
CVE-2026-2812MEDIUM5.3
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026
CVE-2026-2813MEDIUM4.1
  • ArcGIS Server logoArcGIS Server
  • cpe:2.3:a:esri:arcgis_server
NoNoMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management