CVE-2026-33519 is an incorrect authorization vulnerability affecting Esri Portal for ArcGIS versions 11.4, 11.5, and 12.0 across Windows, Linux, and Kubernetes environments. The flaw stems from improper permission validation for developer credentials, potentially allowing unauthorized access to sensitive functions. The vulnerability carries a CVSS score of 9.8 (Critical), indicating severe risk. It is remotely exploitable over the network without requiring user interaction or authentication, and successful exploitation could result in complete compromise of confidentiality, integrity, and availability of affected systems. There is currently no evidence of active exploitation, as the vulnerability is not listed on the KEV catalog and remains inactive on security hotlists. The extremely low EPSS score of 0.0004 suggests minimal real-world exploitation probability at this time, though organizations should prioritize patching given the critical severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.4CPE matchmatch criteria | cpe:2.3:a:esri:portal_for_arcgis:11.4:-:*:*:*:*:*:* | ||
11.5CPE matchmatch criteria | cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:esri:portal_for_arcgis:12.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.