PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-69228 Esri CVE debrief

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. This vulnerability may allow a remote, unauthenticated attacker to access a specific resource that should only be accessible by authenticated users. The affected products include ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0. Users working with these versions are encouraged to patch or upgrade to the latest long-term support release. The CVE record was published on 2026-08-21T21:17:03.423Z and has not been modified since then. The CVSS score is 5.3, indicating a medium severity vulnerability.

Vendor
Esri
Product
Portal for ArcGIS
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0, and administrators responsible for Esri Portal for ArcGIS installations, should prioritize patching or upgrading to mitigate the vulnerability. Security teams and vulnerability management teams should review and apply security updates for affected systems. IT operators and platform administrators should verify affected scope and apply compensating controls if necessary. Additionally, asset owners and risk management teams should be aware of the potential impact on their systems and take appropriate measures.

Technical summary

The vulnerability affects Esri Portal for ArcGIS versions 12.0 and prior, allowing a remote, unauthenticated attacker to access a specific resource that should only be accessible by authenticated users. The affected products include ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0. Users should patch or upgrade to the latest long-term support release. The CVSS score is 5.3, indicating a medium severity vulnerability.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential for remote, unauthenticated access to specific resources.

Recommended defensive actions

  • Patch Esri Portal for ArcGIS versions 12.0 and prior
  • Upgrade to the latest long-term support release
  • Review and apply security updates for ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record indicates a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Evidence is limited to the CVE record and NVD detail. Defenders should verify affected scope, apply patches, and review compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:03.423Z and has not been modified since then.