CVE-2026-69225
Awaiting Analysis
Awaiting Analysis - Queue
Information Disclosure in Esri Portal for ArcGIS
Vulnerability report for CVE-2026-69225, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-21
Last updated on: 2026-09-11
Assigner: Environmental Systems Research Institute, Inc.
Description
Description
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| esri | portal_for_arcgis | 11.5 |
| esri | portal_for_arcgis | 12.0 |
| esri | portal_for_arcgis | 11.5 |
| esri | portal_for_arcgis | 11.5 |
| esri | portal_for_arcgis | 12.0 |
| esri | portal_for_arcgis | 12.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |