CVE-2026-33518

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 May 2026, 18:20

Type Values Removed Values Added
First Time Microsoft
Esri portal For Arcgis
Linux linux Kernel
Esri
Microsoft windows
Linux
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:esri:portal_for_arcgis:11.5:-:*:*:*:*:*:*
References () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin - () https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin - Vendor Advisory

21 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 21:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33518

Mitre link : CVE-2026-33518

CVE.ORG link : CVE-2026-33518


JSON object : View

Products Affected

esri

  • portal_for_arcgis

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-266

Incorrect Privilege Assignment