← All CVEs

CVE-2026-33518

critical · 9.8

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

9.8
CVSS
0.3%
EPSS (exploit prob.)
22nd
EPSS percentile
2026-04-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-266

Affected products

VendorProductAffected versions
esriportal_for_arcgis11.5
linuxlinux_kernelall versions
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-33518