Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33518

32
FAUCET Score

An incorrect privilege assignment vulnerability (CVE-2026-33518) has been identified in Esri Portal for ArcGIS version 11.5 running on both Windows and Linux systems. The flaw enables highly privileged users to create developer credentials that grant elevated permissions beyond their intended scope. This vulnerability carries a critical CVSS score of 9.8 with a network-based attack vector requiring no user interaction or authentication, indicating high exploitability. While the vulnerability has not been added to the Known Exploited Vulnerabilities catalog and shows minimal exploitation activity in the wild with an EPSS score of 0.00041, organizations should still prioritize patching given the critical severity rating and potential for unauthorized access to sensitive resources. The FAUCET risk assessment of 54.0 out of 100 suggests moderate overall concern, though the low current exploitation rate may allow time for coordinated remediation efforts.

Impacted Technologies

VendorProductVersion(s)CPE
11.5CPE matchmatch criteria
cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 2nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

esri.com / arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin
Vendor Advisory