CVE-2026-69228 Details
Description
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| esri portal for arcgis | < 11.1 11.1 - 11.1 security_2024_update1 11.1 security_2024_update2 11.1 security_2025_update1 11.1 security_2025_update2 11.1 security_2025_update3 11.1 security_2026_update2 11.2 11.3 - 11.3 security_2025_update1 11.3 security_2025_update2 11.3 security_2025_update3 11.3 security_2026_update2 11.4 11.5 - 11.5 security_2026_update1 11.5 security_2026_update2 12.0 - 12.0 security_2026_update1 12.0 security_2026_update2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | Initial Analysis | [email protected] |
| Aug 24, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2026 | New CVE Received | [email protected] |