CVE-2026-33519 Details
Description
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
A vulnerability allowing incorrect authorization has been identified in Esri Portal for ArcGIS versions 11.4, 11.5, and 12.0, across Windows, Linux, and Kubernetes platforms. This vulnerability arises from improper validation of permissions linked to developer credentials, which could lead to unauthorized access or actions.
Users of Esri Portal for ArcGIS 11.5 and 12.0 should apply the security patch released on 4/13/2026, with an updated patch version available as of 4/16/2026. Portal for ArcGIS 11.4 users can download the patch released on 4/20/2026. Kubernetes customers should apply ArcGIS Portal for ArcGIS 12.0 Update 3. After applying the patch, it is recommended to review and, if necessary, reissue developer credentials to ensure they have the correct permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| esri portal for arcgis | 11.4 - 11.5 - 12.0 - |
CPE
Remediation
| |
| kubernetes kubernetes | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |