SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9181

CRITICAL · CVSS 9.8 EPSS 0.94% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

Esri ArcGIS Server on Windows and Linux versions 12.0 and prior is vulnerable to a critical directory traversal flaw that allows unauthenticated attackers to send crafted path parameters, potentially leading to the overwriting of sensitive files. Successful exploitation can grant attackers full administrative access, severely compromising the confidentiality, integrity, and availability of the system. Organizations using affected versions of ArcGIS Server should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9181
Severity
CRITICAL
CVSS
9.8
EPSS
0.94%
Windows Linux Kubernetes

Original NVD Description

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

Related CVEs

Other vulnerabilities affecting the same vendor(s)