Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
11.4
affected
11.5
affected
12.0
affected
Description
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Problem types
CWE-266: Incorrect Privilege Assignment (4.19.1)
Product status
11.4
11.5
12.0
References
www.esri.com/...s/administration/april2026_security_bulletin