Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
All (Portal for ArcGIS)
affected
Description
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
All (Portal for ArcGIS)
References
support.esri.com/...-for-arcgis-security-2025-update-3-patch