CVE-2026-2813

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting in a limited confidentiality impact under specific user interaction conditions. The vulnerability affects only the client side navigation logic during authentication and remains confined to the same security boundary. No server side compromise or cross component impact is possible.  This issue affects ArcGIS Server 11.5.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:esri:arcgis_server:11.5:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 May 2026, 18:54

Type Values Removed Values Added
References () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin - () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin - Vendor Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:esri:arcgis_server:11.5:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
CWE CWE-601
First Time Microsoft
Esri arcgis Server
Linux linux Kernel
Esri
Microsoft windows
Linux

20 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 20:16

Updated : 2026-05-21 18:54


NVD link : CVE-2026-2813

Mitre link : CVE-2026-2813

CVE.ORG link : CVE-2026-2813


JSON object : View

Products Affected

esri

  • arcgis_server

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')