Back

MEDIUM

stored cross site scripting issue in Esri Portal for ArcGIS

Published Aug 21, 2026

Description

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Esri
Published Aug 21, 2026
Updated Aug 24, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 24, 2026
NVD
Status Analyzed
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Esri
Published Aug 21, 2026
Updated Aug 24, 2026
Exploited since n/a
EUVD-2026-64082