CVE-2026-33519CRITICAL 9.8EPSS p22.7%
CVE-2026-33519CVE-2026-33519
Description
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.31% probability of exploitation · percentile 22.7% · 2026-06-19T12:03:05Z |
| Published | 2026-04-21 |
| Last modified | 2026-05-18 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Privilege Assignmentcwe-266 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.