← לוח פגיעויות

CVE-2026-33519

קריטית 9.8

תיאור (מקור, אנגלית)

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-25/9/2026
CWE
CWE-266

מוצרים מושפעים

esri: portal for arcgis; kubernetes: kubernetes; linux: linux kernel; microsoft: windows

קישורים