Summary
CVE-2026-13019 is a critical missing authentication for critical function vulnerability (CWE-640) in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can directly access an unprotected API endpoint with no privileges or user interaction required, earning a CVSS v3.1 score of 9.8 (Critical). Esri released the Portal for ArcGIS Security 2026 Update 2 Patch on June 23, 2026, and strongly urges all affected customers to apply it within two weeks.
Technical details
- Root cause: An API endpoint within Portal for ArcGIS is left unprotected, lacking the authentication controls required to restrict access to authorized users — classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password).
- Trigger conditions: The vulnerability can be triggered remotely over the network with no authentication, no elevated privileges, and no user interaction — attackers need only network access to the portal.
- Attack vector: Network-accessible; any internet-exposed Portal for ArcGIS instance is at risk of unauthenticated exploitation.
- Impact: Full compromise of confidentiality, integrity, and availability — an attacker who reaches the unprotected API can read, modify, or disrupt data and services managed by the portal.
Affected software
- Esri Portal for ArcGIS 12.1 (Windows, Linux, Kubernetes)
- Esri Portal for ArcGIS 12.0 (Windows, Linux, Kubernetes)
- Esri Portal for ArcGIS 11.5 (Windows, Linux, Kubernetes)
- Esri Portal for ArcGIS 11.3 (Windows, Linux, Kubernetes)
- Esri Portal for ArcGIS 11.1 (Windows, Linux, Kubernetes)
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Apply the vendor patch immediately: Esri released the Portal for ArcGIS Security 2026 Update 2 Patch on June 23, 2026, and recommends all affected customers apply it within two weeks.
- Windows patch files (per version):
ArcGIS-121-PFA-SEC2026U2-Patch.msp,ArcGIS-120-PFA-SEC2026U2-Patch.msp,ArcGIS-115-PFA-SEC2026U2-Patch.msp,ArcGIS-113-PFA-SEC2026U2-Patch.msp,ArcGIS-111-PFA-SEC2026U2-Patch.msp - Linux: Equivalent
.tarpatch files are available from Esri’s update server. - Full download and installation guidance is available on the Esri support page linked in the references below.
- Windows patch files (per version):
- If immediate patching is not possible: Restrict network access to the Portal for ArcGIS web interface, prioritizing removal of public internet exposure until the patch can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

