PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-69230 Esri CVE debrief

A stored cross-site scripting issue exists in Esri Portal for ArcGIS versions 11.5 and prior. An administratively privileged attacker could inject malicious code that may execute in a victim's browser. Users of ArcGIS Enterprise 11.1, 11.3, and 11.5 should patch, and all users are advised to upgrade to the latest long-term support release. This issue requires immediate attention from administrators and users to prevent potential code execution and unauthorized actions within the Portal for ArcGIS.

Vendor
Esri
Product
Portal for ArcGIS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-11
Advisory published
2026-08-21
Advisory updated
2026-09-11

Who should care

Administrators and users of Esri Portal for ArcGIS, particularly those using ArcGIS Enterprise 11.1, 11.3, and 11.5, should prioritize patching or upgrading to mitigate the stored cross-site scripting vulnerability. This includes reviewing and applying security updates from Esri, monitoring for potential exploitation attempts, and verifying affected scope and remediation steps.

Why it matters

CVE-2026-69230 is a stored cross-site scripting vulnerability in Esri Portal for ArcGIS that requires attention from administrators and users to prevent potential code execution and unauthorized actions.

  • Potential code execution in a victim's browser
  • Possible unauthorized actions within the Portal for ArcGIS
  • Required verification of affected versions and remediation steps
  • Need for administrators to apply patches or upgrades

Technical summary

The vulnerability exists in Esri Portal for ArcGIS versions 11.5 and prior, allowing an administratively privileged attacker to inject malicious code that may execute in a victim's browser. The issue is a stored cross-site scripting vulnerability that requires attention from administrators and users to prevent potential code execution and unauthorized actions within the Portal for ArcGIS. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch and upgrade to the latest long-term support release.

Defensive priority

Administrators of Esri Portal for ArcGIS should prioritize patching or upgrading to mitigate the stored cross-site scripting vulnerability.

Recommended defensive actions

  • Patch or upgrade Esri Portal for ArcGIS to the latest version
  • Review and apply security updates from Esri
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, and a vendor advisory is available from Esri. The Esri advisory provides detailed information about the vulnerability, affected versions, and recommended patches. Defenders should verify the affected scope, apply patches or upgrades, and monitor for potential exploitation attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-69230 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-69230

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-69230 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-69230

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.