CVE-2026-33519

Received
Published: 21 Apr 2026, 20:38
Last modified:21 Apr 2026, 20:38

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Apr 2026, 20:38
Published
Vulnerability first disclosed

Description

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-266Incorrect Privilege Assignment

    A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Systems

  • esriportal for arcgis

    11.4 | 11.5 | 12.0

References (1)