CVE-2026-69225
CVE-2026-69225 is a medium-severity vulnerability in Esri Portal For Arcgis with a CVSS 3.x base score of 5.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-200.
Key facts
- Severity: Medium (CVSS 3.x base score 5.9)
- EPSS exploit prediction: 0% (38th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-200
- Affected product: Esri Portal For Arcgis
- Published:
- Last modified:
Description
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
Frequently asked questions
- What is CVE-2026-69225?
- There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
- How severe is CVE-2026-69225?
- CVE-2026-69225 has a CVSS 3.x base score of 5.9, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-69225 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (38th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-69225?
- CVE-2026-69225 primarily affects Esri Portal For Arcgis. In total, 6 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-69225?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-69225 published?
- CVE-2026-69225 was published on 2026-08-21 and last updated on 2026-09-11.
References
Affected products (6)
- cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:*
- cpe:2.3:a:esri:portal_for_arcgis:11.5:security_2026_update1:*:*:*:*:*:*
- cpe:2.3:a:esri:portal_for_arcgis:11.5:security_2026_update2:*:*:*:*:*:*
- cpe:2.3:a:esri:portal_for_arcgis:12.0:-:*:*:*:*:*:*
- cpe:2.3:a:esri:portal_for_arcgis:12.0:security_2026_update1:*:*:*:*:*:*
- cpe:2.3:a:esri:portal_for_arcgis:12.0:security_2026_update2:*:*:*:*:*:*
More vulnerabilities in Esri Portal For Arcgis
- CVE-2024-25693 — Critical (CVSS 9.9): There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote,…
- CVE-2026-13019 — Critical (CVSS 9.8): Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for…
- CVE-2026-33519 — Critical (CVSS 9.8): An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and…
- CVE-2026-33518 — Critical (CVSS 9.8): An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows…
- CVE-2025-2538 — Critical (CVSS 9.8): A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4…
- CVE-2025-4967 — Critical (CVSS 9.1): Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF…
All CVEs affecting Esri Portal For Arcgis →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-92960 — Critical (CVSS 10.0): vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…
- CVE-2026-92947 — Critical (CVSS 10.0): vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…
- CVE-2026-70478 — Critical (CVSS 10.0): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →