An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. | |
| Title | Incorrect privilege assignment in Portal for ArcGIS | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2026-04-21T20:37:52.198Z
Reserved: 2026-03-20T17:25:24.409Z
Link: CVE-2026-33518
No data.
Status : Received
Published: 2026-04-21T21:16:29.490
Modified: 2026-04-21T21:16:29.490
Link: CVE-2026-33518
No data.
OpenCVE Enrichment
Updated: 2026-04-22T02:15:05Z
Weaknesses