


Perceptive Security
SOC/SIEM Consultancy

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create develop…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 22:04:46
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
A privilege assignment vulnerability in Esri Portal for ArcGIS 11.5 affects both Windows and Linux platforms. The vulnerability allows highly privileged users to create developer credentials that may grant more privileges than expected. This represents an incorrect privilege assignment issue that could lead to privilege escalation. The vulnerability impacts enterprise GIS systems and could potentially allow unauthorized access to sensitive geospatial data and administrative functions.
Technical details
Mitigation steps:
Affected products:
Esri Portal for ArcGIS 11.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33518
https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/april2026_security_bulletin
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
