CVE-2026-33519
CRITICAL
9.8
CVSS 3.1
Description
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Esri | Portal for ArcGIS | Windows,Linux,Kubernetes | 11.4, 11.5, 12.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-266 | cna | CWE-266: Incorrect Privilege Assignment (4.19.1) |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (1)