CVE-2026-2812 PUBLISHED

Improper Authentication issue in ArcGIS Server

Assigner: Esri
Reserved: 19.02.2026 Published: 20.05.2026 Updated: 20.05.2026

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Esri
Product ArcGIS Server
Versions Default: unaffected
  • affected from 11.1 to 12.0 (incl.)

References

Problem Types

  • CWE-287 Improper Authentication CWE