CVE-2026-1446

There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard local user access. A local attacker can supply malicious strings that may be rendered and executed when a specific dialog within ArcGIS Pro is opened. This issue is fixed in ArcGIS Pro version 3.6.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:15

Type Values Removed Values Added
Summary
  • (es) Hay un problema de Cross-Site Scripting (XSS) en las versiones 3.6.0 y anteriores de Esri ArcGIS Pro. ArcGIS Pro es una aplicación de escritorio, y la explotación se limita a usuarios locales que interactúan con la aplicación; no se requiere ningún rol privilegiado ni permisos elevados más allá del acceso estándar de usuario local. Un atacante local puede proporcionar cadenas maliciosas que pueden ser renderizadas y ejecutadas cuando se abre un diálogo específico dentro de ArcGIS Pro. Este problema está solucionado en la versión 3.6.1 de ArcGIS Pro.

06 Feb 2026, 07:16

Type Values Removed Values Added
Summary (en) There is a Cross Site Scripting issue in Esri ArcGIS Pro versions 3.6.0 and earlier. A local attacker could supply malicious strings into ArcGIS Pro which may execute when a specific dialog is opened. This issue is fixed in ArcGIS Pro 3.6.1. (en) There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard local user access. A local attacker can supply malicious strings that may be rendered and executed when a specific dialog within ArcGIS Pro is opened. This issue is fixed in ArcGIS Pro version 3.6.1.

02 Feb 2026, 13:31

Type Values Removed Values Added
First Time Esri arcgis Pro
Esri
CPE cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*
References () https://www.esri.com/arcgis-blog/products/arcgis-pro/administration/arcgis-pro-3-6-1-patch - () https://www.esri.com/arcgis-blog/products/arcgis-pro/administration/arcgis-pro-3-6-1-patch - Vendor Advisory

26 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 18:16

Updated : 2026-06-17 10:15


NVD link : CVE-2026-1446

Mitre link : CVE-2026-1446

CVE.ORG link : CVE-2026-1446


JSON object : View

Products Affected

esri

  • arcgis_pro
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')