An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
References
| Link | Resource |
|---|---|
| https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
18 May 2026, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Microsoft
Esri portal For Arcgis Linux linux Kernel Esri Microsoft windows Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:* |
|
| References | () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin - Vendor Advisory |
21 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 21:16
Updated : 2026-06-17 10:37
NVD link : CVE-2026-33518
Mitre link : CVE-2026-33518
CVE.ORG link : CVE-2026-33518
JSON object : View
Products Affected
esri
- portal_for_arcgis
microsoft
- windows
linux
- linux_kernel
CWE
CWE-266
Incorrect Privilege Assignment
