HarborGuard / CVE
Back to search
CRITICALCVE-2026-33518Published Modified CNA Esri

CVE-2026-33518: Incorrect privilege assignment in Portal for ArcGIS

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Esri / Portal for ArcGIS
    11.5
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
CVE-2026-33518: Incorrect privilege assignment in Portal for ArcGIS | HarborGuard CVE