CVE-2026-13019

portal_for_arcgis: Weak Password Recovery Mechanism for Forgotten Password (CVE-2026-13019)

criticalEPSS 0.9%

Affected

  • esri/portal_for_arcgis between *..12.1

Description

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other unsupported versions may also be affected. Esri recommends that users apply the Portal for ArcGIS Security 2026 Update 2 Patch to remediate this vulnerability.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

esriportal_for_arcgis
12.1

Metrics

9.8
Source: nvd-v3
56.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-07 16:40 UTC
CWE-640

Weakness classes (CWE)

  • CWE-640Base

    Weak Password Recovery Mechanism for Forgotten Password

    The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-29 20:17 UTC· psirt@esri.com
    • Description: Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. → Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other unsupported versions may also be affected. Esri recommends that users apply the Portal for ArcGIS Security 2026 Update 2 Patch to remediate this vulnerability.
    • Reference: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
    • Reference: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
    • Reference Type: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin Types: Vendor Advisory
  2. CVE Modified2026-07-08 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-13019","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-13019","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…

Linked advisories