An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. | |
| Title | Incorrect privilege assignment in Portal for ArcGIS | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2026-04-21T20:37:52.198Z
Reserved: 2026-03-20T17:25:24.409Z
Link: CVE-2026-33518
No data.
Status : Received
Published: 2026-04-21T21:16:29.490
Modified: 2026-04-21T21:16:29.490
Link: CVE-2026-33518
No data.
OpenCVE Enrichment
Updated: 2026-04-22T02:15:05Z