An incorrect privilege assignment vulnerability (CVE-2026-33518) has been identified in Esri Portal for ArcGIS version 11.5 running on both Windows and Linux systems. The flaw enables highly privileged users to create developer credentials that grant elevated permissions beyond their intended scope. This vulnerability carries a critical CVSS score of 9.8 with a network-based attack vector requiring no user interaction or authentication, indicating high exploitability. While the vulnerability has not been added to the Known Exploited Vulnerabilities catalog and shows minimal exploitation activity in the wild with an EPSS score of 0.00041, organizations should still prioritize patching given the critical severity rating and potential for unauthorized access to sensitive resources. The FAUCET risk assessment of 54.0 out of 100 suggests moderate overall concern, though the low current exploitation rate may allow time for coordinated remediation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.5CPE matchmatch criteria | cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.