AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-13020

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A weak password recovery mechanism in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes allows remote, unauthorized attackers to take over user accounts. This vulnerability poses a significant risk to user data integrity and system security. ArcGIS Administrators should prioritize implementing a secure email server configuration to enhance the password recovery process and mitigate potential account takeover risks.

CVE
CVE-2026-13020
Severity
HIGH
CVSS
8.1
EPSS
0.27%
Windows Linux Kubernetes

Original NVD Description

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

Related CVEs

Other vulnerabilities affecting the same vendor(s)