CVE-2026-9181
arcgis_server: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-9181)
Beschreibung
Esri ArcGIS Server enthält eine Verzeichnis-Traversierungs-Schwachstelle. ArcGIS Enterprise auf Kubernetes ist nicht betroffen. Ein unauthentifizierter Angreifer könnte diese Schwachstelle ausnutzen, indem er manipulierte Pfadparameter sendet. Eine erfolgreiche Ausnutzung könnte es ermöglichen, sensible Dateien im System zu überschreiben. Die Missbrauchsmöglichkeit dieser Schwachstelle kann vollständigen administrativen Zugriff auf ArcGIS Server gewähren und hat einen hohen Einfluss auf Vertraulichkeit, Integrität und Verfügbarkeit. Diese Schwachstelle betrifft alle Versionen von ArcGIS Server unter Windows und Linux 12.0 und früher. Sie beeinträchtigt nicht ArcGIS Enterprise für Kubernetes.
Metriken
Weakness-Klassen (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-08 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-9181","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI… → {"id":"CVE-2026-9181","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- Initial Analysis2026-07-08 03:09 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CPE Configuration: AND OR *cpe:2.3:a:esri:arcgis_server:*:*:*:*:*:*:*:* versions up to (including) 12.0 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
- Reference Type: Environmental Systems Research Institute, Inc.: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/may-2026-arcgis-security-bulletin Types: Vendor Advisory
- CVE Modified2026-07-06 20:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-9181","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- New CVE Received2026-07-06 19:17 UTC· psirt@esri.com
- Affected: ArcGIS Server
- Description: ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-22
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
esri
arcgis_server12.0