CVE-2026-69225

Summary

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

Affected Software

VendorProductVersion RangeStatus
EsriPortal for ArcGIS11.5 <= 12.0affected

Weaknesses

  • CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

References