Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13020: Portal for ArcGIS Weak Password Recovery Exposes User Accounts

CVE-2026-13020 CVE-2026-13020
Summary

A security weakness in Portal for ArcGIS versions 12.1 and earlier allows an unauthorized attacker to take control of a user's account. This affects Windows, Linux, and Kubernetes systems. To protect user accounts, administrators should set up an email server with ArcGIS Enterprise to enable users to reset their own passwords.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
esri portal for arcgis < 12.1
esri portal_for_arcgis <= 12.1
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Original title
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume own...
Original description
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
nvd CVSS3.1 8.1
Vulnerability type
CWE-640
Published: 7 Jul 2026 · Updated: 20 Jul 2026 · First seen: 7 Jul 2026