CVE-2026-33518
Incorrect Privilege Assignment in Esri Portal for ArcGIS
Publication date: 2026-04-21
Last updated on: 2026-04-21
Assigner: Environmental Systems Research Institute, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| esri | portal_for_arcgis | 11.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an incorrect privilege assignment issue found in Esri Portal for ArcGIS 11.5 on both Windows and Linux platforms. It allows highly privileged users to create developer credentials that may have more privileges than intended or expected.
How can this vulnerability impact me? :
Because the vulnerability allows the creation of developer credentials with excessive privileges, it can lead to unauthorized access or actions within the system. This could result in a compromise of confidentiality, integrity, and availability of the affected system.