Advisory ID: ngCERT-2026-080005
Damage: Critical
Probability: High
Platform(s): Windows, Linux, and Kubernetes (Esri Portal for ArcGIS)
SUMMARY
ngCERT warns organisations using Esri Portal for ArcGIS of a critical authentication bypass vulnerability tracked as CVE-2026-13019. The flaw affects Portal for ArcGIS versions 12.1 and earlier running on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can access an unprotected API endpoint without any credentials or user interaction. The vulnerability carries a CVSS v3.1 score of 9.8 (Critical). Esri has released a security patch, and all affected organisations are strongly advised to apply it immediately.
DESCRIPTION
CVE-2026-13019 is a missing authentication for a critical function vulnerability (CWE-306 / CWE-640) in Esri Portal for ArcGIS. An API endpoint within the product lacks proper authentication controls, allowing a remote attacker to invoke it without providing valid credentials. Successful exploitation requires no privileges and user interaction. Since the vulnerable endpoint is network-accessible, attackers can exploit it remotely over the internet or internal networks. The vulnerability impacts confidentiality, integrity, and availability of the affected system. Esri published the fix in the Portal for ArcGIS Security 2026 Update 2 Patch (released June 2026).
CONSEQUENCES
Successful exploitation of CVE-2026-13019 may result in:
- Unauthorised access to critical API functions.
- Compromise of sensitive geospatial and organisational data.
- Potential modification or deletion of portal content and configurations.
- Full impact on system confidentiality, integrity, and availability.
- Possible further lateral movement within the network.
SOLUTION/MITIGATION
ngCERT recommends the following:
- Immediately apply the Portal for ArcGIS Security 2026 Update 2 Patch released by Esri.
- Upgrade to a fixed version of Portal for ArcGIS as advised by the vendor.
- Restrict network access to the Portal for ArcGIS management and API interfaces using firewalls or network segmentation.
- Monitor logs for any unauthenticated API access attempts.
- Conduct a security assessment of all ArcGIS Portal deployments.
- Implement the principle of least privilege and multi-factor authentication where possible.
- Report any confirmed exploitation or related incidents to ngCERT for further assistance and coordination.
HYPERLINK
- https://www.cve.org/CVERecord?id=CVE-2026-13019
- https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
- https://www.ionix.io/threat-center/cve-2026-13019/
- https://www.sentinelone.com/vulnerability-database/cve-2026-13019/
- https://msftnewsnow.com/microsoft-code-of-conduct-phishing-aitm-token-thef/