- What: Multiple vulnerabilities in ESRI Portal for ArcGIS allow XSS and authentication bypass
- Impact: Attackers may inject malicious scripts or access sensitive data
[WID-SEC-2026-2966] ESRI Portal für ArcGIS: Mehrere Schwachstellen CVSS Base Score 6.1 (mittel) CVSS Temporal Score 5.3 (mittel) Remoteangriff ja Datum 23.08.2026 Stand 24.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung ArcGIS ist ein Geoinformationssystem. Produkte 23.08.2026 ESRI ArcGIS Portal <2026 Security Update 3 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in ESRI Portal für ArcGIS ausnutzen, um Cross-Site-Scripting- und HTML-Injection-Angriffe durchzuführen, die Authentifizierung zu umgehen oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben