Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9182: ArcGIS Server allows attackers to upload malicious files

CVE-2026-9182 CVE-2026-9182
Summary

ArcGIS Server has a security weakness that lets attackers upload files without permission. This could allow them to do harm to your system. To protect yourself, make sure you keep ArcGIS Server up to date with the latest security patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
esri arcgis_server <= 12.0
cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:*
esri arcgis server <= 12.0
Original title
Unvalidated File Upload vulnerability in ArcGIS Server.
Original description
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.
nvd CVSS3.1 5.3
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026