ArcGIS Blog

Administration

ArcGIS Enterprise

August 2026 ArcGIS Security Bulletin

By Randall Williams and Mark Bierman and Michael Young

The Portal for ArcGIS 2026 Security Update 3 patch has been released and is available here.

This patch resolves several medium and low severity security vulnerabilities in Portal for ArcGIS versions 12.1 and earlier.

This patch was released August 4th, 2026. We strongly encourage ArcGIS Enterprise customers apply this patch within the next two weeks to minimize risk.

Patch Notes:

  • Cumulative – This patch is cumulative and does not require that you install any previous Portal for ArcGIS Security patches prior to installing this patch – Using the Patch Notification Utility can help ease this process. This patch is NOT dependent on other patches to be in place.
  • Esri has reserved CVE identifiers for the vulnerabilities fixed in this patch.
  • Mitigation – In order to mitigate these vulnerabilities, we strongly recommend all ArcGIS Enterprise customers install this patch as soon as possible.
    • Your Web Application Firewall (WAF) will help to block malicious patterns.
    • Implementing the basic profile in the ArcGIS Hardening guide will reduce exposure.

Vulnerability Details 

CVE-2026-69234: There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 6.1 (medium)
  • Temporal CVSSv3.1: 5.8 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69235: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 6.1 (medium)
  • Temporal CVSSv3.1: 5.8 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69236: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 6.1 (medium)
  • Temporal CVSSv3.1: 5.8 (medium)
  • Affected: All Portal for ArcGIS versions 12.1 and prior

CVE-2026-69224: There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
  • Base CVSSv3.1: 5.9 (medium)
  • Temporal CVSSv3.1: 5.7 (medium)
  • Affected: All Portal for ArcGIS versions 12.0 and prior

CVE-2026-69225: There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
  • Base CVSSv3.1: 5.9 (medium)
  • Temporal CVSSv3.1: 5.7 (medium)
  • Affected: Portal for ArcGIS versions 11.5 and 12.0 only

CVE-2026-69230: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 5.5 (medium)
  • Temporal CVSSv3.1: 5.3 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69231: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 5.5 (medium)
  • Temporal CVSSv3.1: 5.3 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69232: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 5.5 (medium)
  • Temporal CVSSv3.1: 5.3 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69233: There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 5.5 (medium)
  • Temporal CVSSv3.1: 5.3 (medium)
  • Affected: All Portal for ArcGIS versions 11.5 and prior

CVE-2026-69229: There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 5.4 (medium)
  • Temporal CVSSv3.1: (5.2 medium)
  • Affected: All Portal for ArcGIS versions 12.0 and prior

CVE-2026-69228: There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-306: Missing Authentication for Critical Function
  • Base CVSSv3.1: 5.3 (medium)
  • Temporal CVSSv3.1: 5.1 medium
  • Affected: All Portal for ArcGIS versions 12.0 and prior

CVE-2026-69237: There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 3.8 (low)
  • Temporal CVSSv3.1: (3.7 low)
  • Affected: All Portal for ArcGIS versions 11.3, 11.1 and prior

CVE-2026-69238: There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

  • CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • Base CVSSv3.1: 3.5 (low)
  • Temporal CVSSv3.1: (3.4 low)
  • Affected: All Portal for ArcGIS versions 11.3, 11.1 and prior

 

 

Share this article