PatchSiren cyber security CVE debrief
CVE-2026-69230 Esri CVE debrief
There is a stored cross-site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior. This vulnerability allows a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. The issue impacts users working with ArcGIS Enterprise 11.1, 11.3, and 11.5, and administrators of Esri Portal for ArcGIS. Security teams responsible for vulnerability management and patching should also be aware of this issue. The CVE record was published on 2026-08-21T21:17:03.670Z and has not been modified since then. Users are encouraged to patch and upgrade to the latest long-term support release.
- Vendor
- Esri
- Product
- Portal for ArcGIS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5; administrators of Esri Portal for ArcGIS; and security teams responsible for vulnerability management and patching should be aware of this stored cross-site scripting issue. These stakeholders should review the official CVE record and consider patching or upgrading to the latest long-term support release. Security teams should also monitor for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM, indicating a medium severity vulnerability that requires attention for affected systems. Users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, remediated assets should be retested, and the item should be closed only after evidence is documented. The goal is to ensure that affected systems are properly secured and that the vulnerability is fully remediated. This involves a thorough review of the affected systems, implementation of patches or mitigations, and verification of the effectiveness of these measures. By taking these steps, organizations can minimize the risk associated with this vulnerability and protect their systems from potential attacks. The CVE record provides additional context and details about the vulnerability, including its CVSS score and severity rating. Users should consult this record and other official advisories to ensure they have a comprehensive understanding of the issue and the necessary steps to address it. Overall, a
Technical summary
A stored cross-site scripting issue exists in Esri Portal for ArcGIS versions 11.5 and prior. This vulnerability allows a remote, administratively privileged attacker to inject malicious code. The issue affects users working with ArcGIS Enterprise 11.1, 11.3, and 11.5. Administrators of Esri Portal for ArcGIS should prioritize patching for versions 11.5 and prior. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM.
Defensive priority
Medium severity vulnerability in Esri Portal for ArcGIS, patching recommended for versions 11.5 and prior.
Recommended defensive actions
- Patch Esri Portal for ArcGIS versions 11.5 and prior
- Upgrade to the latest long-term support release
- Inventory and verify affected systems
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Stored cross-site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior; remote, administratively privileged attacker could inject malicious code. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. The CVE record was published on 2026-08-21T21:17:03.670Z and has not been modified since then.
Official resources
-
CVE-2026-69230 CVE record
CVE.org
-
CVE-2026-69230 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:03.670Z and has not been modified since then.