PatchSiren cyber security CVE debrief
CVE-2026-69229 Esri CVE debrief
The CVE record describes an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. This vulnerability allows remote, authenticated attackers to insert arbitrary HTML into the Portal for ArcGIS Home application. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Limited information is available; further verification is needed.
- Vendor
- Esri
- Product
- Portal for ArcGIS
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0; administrators of Esri Portal for ArcGIS; and security teams responsible for vulnerability management and patching are advised to take action. The vulnerability allows remote, authenticated attackers to insert arbitrary HTML into the Portal for ArcGIS Home application, which could potentially lead to security issues if exploited. Limited information is available; further verification is needed to assess the full impact of this vulnerability. Users are encouraged to patch and upgrade to the latest long-term support release. Security teams should review the CVE record and apply necessary updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented. The CVE record indicates an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. Limited information available; further verification needed. The CVE record was published on 2026-08-21T21:17:03.547Z and has not been modified since then. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. The CVE record describes an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior, allowing remote, authenticated attackers to insert arbitrary HTML into the Portal for ArcGIS Home application. Users are advised to upgrade to the latest long-term support release. The CVE record was published on 2026-08-21T21:17:03.547Z and has not been modified since then. Limited information is available; further verification is needed to assess the full impact of this vulnerability. Security teams should review the CVE record and apply necessary updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while is
Technical summary
The CVE record describes an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior, allowing remote, authenticated attackers to insert arbitrary HTML into the Portal for ArcGIS Home application. Users are advised to upgrade to the latest long-term support release. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. The CVE record was published on 2026-08-21T21:17:03.547Z and has not been modified since then.
Defensive priority
Medium priority given the CVSS score of 5.4 and the potential for authenticated attackers to inject HTML.
Recommended defensive actions
- Patch Esri Portal for ArcGIS to the latest long-term support release
- Verify and apply updates for ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0
- Monitor for suspicious activity in Portal for ArcGIS Home application
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record indicates an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. Limited information available; further verification needed.
Official resources
-
CVE-2026-69229 CVE record
CVE.org
-
CVE-2026-69229 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:03.547Z and has not been modified since then.