CVE-2026-33519: Esri Portal For Arcgis
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Affected products
- Esri Portal For Arcgis: version 11.4 only; version 11.5 only; version 12.0 only
Published 2026-04-21. Last modified 2026-06-17.