Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9182: ArcGIS Server allows attackers to upload malicious files
CVE-2026-9182
CVE-2026-9182
Summary
ArcGIS Server has a security weakness that lets attackers upload files without permission. This could allow them to do harm to your system. To protect yourself, make sure you keep ArcGIS Server up to date with the latest security patches.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| esri | arcgis_server |
<= 12.0 cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* |
| esri | arcgis server | <= 12.0 |
Original title
Unvalidated File Upload vulnerability in ArcGIS Server.
Original description
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.
nvd CVSS3.1
5.3
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026