Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13019: Unauthenticated Access to Esri Portal for ArcGIS API

CVE-2026-13019 CVE-2026-13019
Summary

Esri Portal for ArcGIS versions 12.1 and earlier have a security issue that allows attackers to access certain parts of the system without a password. This is a concern for organizations that use this software, as it could lead to unauthorized access and data exposure. Update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
esri portal for arcgis < 12.1
Original title
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to acce...
Original description
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
nvd CVSS3.1 9.8
Vulnerability type
CWE-640
Published: 7 Jul 2026 · Updated: 23 Jul 2026 · First seen: 7 Jul 2026