← All CVEs

CVE-2026-33519

critical · 9.8

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

9.8
CVSS
0.3%
EPSS (exploit prob.)
24th
EPSS percentile
2026-04-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-266

Affected products

VendorProductAffected versions
esriportal_for_arcgis11.4
esriportal_for_arcgis11.5
esriportal_for_arcgis12.0
kuberneteskubernetesall versions
linuxlinux_kernelall versions
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-33519