← back
CVE-2026-33519criticalCWE-266

Incorrect privilege assignment in Portal for ArcGIS

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Esri · Portal for ArcGIS