PatchSiren cyber security CVE debrief
CVE-2026-69230 Esri CVE debrief
A stored cross-site scripting issue exists in Esri Portal for ArcGIS versions 11.5 and prior. An administratively privileged attacker could inject malicious code that may execute in a victim's browser. Users of ArcGIS Enterprise 11.1, 11.3, and 11.5 should patch, and all users are advised to upgrade to the latest long-term support release. This issue requires immediate attention from administrators and users to prevent potential code execution and unauthorized actions within the Portal for ArcGIS.
- Vendor
- Esri
- Product
- Portal for ArcGIS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-11
Who should care
Administrators and users of Esri Portal for ArcGIS, particularly those using ArcGIS Enterprise 11.1, 11.3, and 11.5, should prioritize patching or upgrading to mitigate the stored cross-site scripting vulnerability. This includes reviewing and applying security updates from Esri, monitoring for potential exploitation attempts, and verifying affected scope and remediation steps.
Why it matters
CVE-2026-69230 is a stored cross-site scripting vulnerability in Esri Portal for ArcGIS that requires attention from administrators and users to prevent potential code execution and unauthorized actions.
- Potential code execution in a victim's browser
- Possible unauthorized actions within the Portal for ArcGIS
- Required verification of affected versions and remediation steps
- Need for administrators to apply patches or upgrades
Technical summary
The vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior, allowing an administratively privileged attacker to inject malicious code that may execute in a victim's browser. The issue is a stored cross-site scripting vulnerability that requires attention from administrators and users to prevent potential code execution and unauthorized actions within the Portal for ArcGIS. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch and upgrade to the latest long-term support release.
Defensive priority
Administrators of Esri Portal for ArcGIS should prioritize patching or upgrading to mitigate the stored cross-site scripting vulnerability.
Recommended defensive actions
- Patch or upgrade Esri Portal for ArcGIS to the latest version
- Review and apply security updates from Esri
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, and a vendor advisory is available from Esri. The Esri advisory provides detailed information about the vulnerability, affected versions, and recommended patches. Defenders should verify the affected scope, apply patches or upgrades, and monitor for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-69230 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-69230
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-69230 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-69230
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.