CVE-2026-13019
portal_for_arcgis: Weak Password Recovery Mechanism for Forgotten Password (CVE-2026-13019)
Affected
- esri/portal_for_arcgis
between *..12.1
Description
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other unsupported versions may also be affected. Esri recommends that users apply the Portal for ArcGIS Security 2026 Update 2 Patch to remediate this vulnerability.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
12.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-640Base
Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-29 20:17 UTC· psirt@esri.com
- Description: Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. → Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other unsupported versions may also be affected. Esri recommends that users apply the Portal for ArcGIS Security 2026 Update 2 Patch to remediate this vulnerability.
- Reference: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
- Reference: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin
- Reference Type: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin Types: Vendor Advisory
- CVE Modified2026-07-08 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-13019","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-13019","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…