CVE-2026-33519: Esri Portal For Arcgis

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Affected products

  • Esri Portal For Arcgis: version 11.4 only; version 11.5 only; version 12.0 only

Published 2026-04-21. Last modified 2026-06-17.