The Portal for ArcGIS 2026 Security Update 4 patch has been released and is available here.
This patch resolves one medium and two critical severity security vulnerabilities in Portal for ArcGIS versions 12.1 and earlier.
This patch was released September 24th, 2026. We strongly encourage ArcGIS Enterprise customers apply this patch ASAP to minimize risk.
Patch Notes:
- Cumulative – This patch is cumulative and does not require that you install any previous Portal for ArcGIS Security patches prior to installing this patch – Using the Patch Notification Utility can help ease this process. This patch is NOT dependent on other patches to be in place.
- Esri has reserved CVE identifiers for the vulnerabilities fixed in this patch.
- Mitigation – In order to mitigate these vulnerabilities, we strongly recommend all ArcGIS Enterprise customers install this patch as soon as possible.
- Your Web Application Firewall (WAF) will help to block malicious patterns.
- Implementing the basic profile in the ArcGIS Hardening guide will reduce exposure.
- CVE-2026-69227 is mitigated by removing any configured default role. If a default role is not defined, an account creation restrictions cannot be bypassed.
Vulnerability Details
- CWE-306: Missing Authentication for Critical Function
- Base CVSSv3.1: 9.8 (critical)
- Temporal CVSSv3.1: 9.4 (critical)
- Affected: All Portal for ArcGIS versions 12.1 and prior
- CWE-863 Incorrect Authorization
- Base CVSSv3.1: 6.5 (medium)
- Temporal CVSSv3.1: 6.2 (medium)
- Affected: All Portal for ArcGIS versions 12.1 and prior
- CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (‘LDAP Injection’)
- Base CVSSv3.1: 5.5 (medium)
- Temporal CVSSv3.1: 5.3 (medium)
- Affected: All Portal for ArcGIS versions 12.1 and prior
Commenting is not enabled for this article.