VYPR
High severity8.1NVD Advisory· Published Jul 7, 2026· Updated Jul 9, 2026

CVE-2026-13020

CVE-2026-13020

Description

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

Affected products

2
  • cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*range: <=12.1
    • (no CPE)range: <=12.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.