Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-13019 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-13019 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-13019 is a missing authentication for a critical function vulnerability in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes environments.

Technical Detail

The flaw exists because one or more critical functions within Esri Portal for ArcGIS do not enforce authentication, allowing a remote, unauthenticated attacker to access those functions directly over the network. An attacker can trigger this by sending crafted requests to the exposed endpoint without supplying any credentials or session tokens. Depending on the nature of the unprotected function, exploitation could result in unauthorized data access, privilege escalation, or full administrative control over the portal instance.

Exploitation Status

No known exploit has been publicly documented or observed at this time. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the critical CVSS score of 9.8 and the unauthenticated remote attack vector make this a high-priority patching target regardless of current exploit availability.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Organizations running Esri Portal for ArcGIS version 12.1 or earlier on any supported platform, including Windows, Linux, and Kubernetes, should apply the vendor-supplied patch as soon as it becomes available and treat this as a critical priority given the unauthenticated remote exploitation path. Until patching is complete, administrators should restrict network access to the Portal for ArcGIS web interface using perimeter controls, firewall rules, or reverse proxy authentication layers to limit exposure to trusted networks only. Review web server and application access logs for unexpected or anomalous requests to Portal endpoints, particularly those that do not carry authentication headers or session tokens. Confirm with Esri's security advisories for the specific patched version and any additional hardening guidance applicable to Kubernetes-based deployments, which may require separate remediation steps from traditional on-premises installations.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →