Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.
References
| Link | Resource |
|---|---|
| https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/may-2026-arcgis-security-bulletin | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-06 19:17
Updated : 2026-07-08 16:16
NVD link : CVE-2026-9182
Mitre link : CVE-2026-9182
CVE.ORG link : CVE-2026-9182
JSON object : View
Products Affected
esri
- arcgis_server
microsoft
- windows
linux
- linux_kernel
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
