CVE-2026-13020: Weak Password Recovery in Esri Portal for ArcGIS—Analysis & Patching Guide
Esri's Portal for ArcGIS contains a flaw in how it handles forgotten password requests. An attacker can exploit this weakness to take over user accounts without authorization. The vulnerability affects Portal for ArcGIS version 12.1 and earlier on Windows, Linux, and Kubernetes deployments. Organizations running these versions should prioritize patching or implementing the recommended email server configuration to enable secure self-service password recovery.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-640
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-07-07 / 2026-07-09
NVD description (verbatim)
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13020 is a weak password recovery mechanism vulnerability (CWE-640) in Esri Portal for ArcGIS that allows remote attackers to assume ownership of user accounts. The flaw exists in versions 12.1 and earlier across Windows, Linux, and Kubernetes platforms. The CVSS 3.1 score of 8.1 (HIGH) reflects the network-accessible nature of the vulnerability (AV:N), its impact on confidentiality, integrity, and availability (C:H/I:H/A:H), and the relatively high complexity needed to exploit it (AC:H). The attack requires no privileges or user interaction, making account takeover feasible for unauthenticated adversaries.
Business impact
Successful exploitation enables attackers to compromise user accounts on Portal for ArcGIS instances, potentially granting unauthorized access to geospatial data, administrative functions, and integrated enterprise systems. This can lead to data theft, unauthorized modifications to maps and analytics, disruption of GIS-dependent business processes, and reputational harm. Organizations using Portal for ArcGIS in critical infrastructure, utilities, or government contexts face elevated operational risk.
Affected systems
Esri Portal for ArcGIS version 12.1 and earlier is vulnerable on Windows, Linux, and Kubernetes environments. Later versions are not confirmed affected. The vulnerability also involves dependencies or platforms including Windows and Linux kernels, which may be targeted as part of the attack chain depending on deployment architecture. Kubernetes deployments running Portal for ArcGIS require particular attention due to the multi-tenant nature of container orchestration.
Exploitability
The vulnerability is exploitable remotely without authentication or user interaction, which typically indicates high real-world risk. However, the CVSS Attack Complexity (AC:H) suggests that successful exploitation requires specific conditions—such as knowledge of a valid username, timing constraints, or particular system configurations—that moderately hinder opportunistic attacks. Exploitation does not require privilege escalation. The flaw is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the advisory date, meaning active in-the-wild exploitation has not been formally documented, though this does not preclude targeted or private exploitation.
Remediation
Upgrade Portal for ArcGIS to a version after 12.1. Immediately, administrators should configure an email server with ArcGIS Enterprise to enable secure, self-service password recovery mechanisms, which mitigates the weak mechanism present in affected versions. This approach allows users to verify their identity through email before resetting passwords. Standard administrator-initiated password reset capabilities are unaffected and remain available as a fallback. Verify patching against Esri's official security advisories and release notes.
Patch guidance
Upgrade Portal for ArcGIS beyond version 12.1 as soon as feasible. Consult Esri's official security advisories for specific patched version numbers and compatibility information for your platform (Windows, Linux, or Kubernetes). Test patches in non-production environments to ensure compatibility with custom integrations and dependent services. While patching is underway, prioritize enabling email-based password recovery as an interim control to reduce exposure.
Detection guidance
Monitor Portal for ArcGIS authentication logs for unusual password reset or account recovery requests, particularly those involving failed attempts, rapid successive requests, or access patterns inconsistent with normal user behavior. Track failed login attempts followed by password recovery attempts, which may indicate reconnaissance. Review audit logs for unexpected changes to account ownership or permissions. Network-level detection should flag repeated unauthenticated connections to Portal password recovery endpoints from the same source.
Why prioritize this
This vulnerability scores HIGH on CVSS (8.1) due to its network accessibility, lack of authentication requirement, and direct impact on account security and data confidentiality. Although not yet listed on CISA's KEV, the mechanism for account takeover is straightforward enough that exploitation is likely if left unpatched. Organizations should prioritize remediation within their standard vulnerability management windows, with expedited patching for instances handling sensitive geospatial or administrative data.
Risk score, explained
The CVSS 3.1 score of 8.1 reflects the combination of network accessibility (AV:N), no required privileges or user interaction (PR:N/UI:N), high impact across confidentiality, integrity, and availability (C:H/I:H/A:H), and unchanged scope (S:U). The Attack Complexity of High (AC:H) prevents a higher score, indicating that successful exploitation depends on non-trivial conditions such as valid account names or system configuration knowledge. In practice, the score appropriately reflects a serious vulnerability that threatens account security but requires some attacker knowledge or preparation.
Frequently asked questions
What happens if I cannot patch immediately?
Enable email-based password recovery by configuring an email server with ArcGIS Enterprise. This addresses the weak mechanism in the vulnerable versions and significantly reduces the attack surface while you plan and execute the upgrade.
Does this vulnerability affect my administrative password reset capabilities?
No. The vulnerability specifically targets the user self-service password recovery mechanism. Administrators retain the ability to reset user passwords through standard administrative functions.
Are Kubernetes deployments at higher risk than Windows or Linux?
All platforms (Windows, Linux, Kubernetes) are equally vulnerable to the flaw itself. However, Kubernetes environments may be more attractive to attackers due to multi-tenancy and potential lateral movement possibilities if a single Portal instance is compromised.
Is there active exploitation in the wild?
As of the advisory date, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, meaning active, widespread exploitation has not been formally documented. This does not guarantee absence of targeted or private exploitation. Upgrade promptly regardless.
This analysis is provided for informational purposes and does not constitute legal, compliance, or professional security advice. Organizations must verify all technical details, patch version numbers, and remediation steps against official Esri security advisories and their own environments. Exploit code, proof-of-concept demonstrations, or weaponization techniques are not discussed in this advisory. Security decisions should be made in consultation with qualified security professionals and vendors. The vulnerability status and exploit landscape may change; consult authoritative sources regularly for updates. Source: NVD (public-domain), retrieved 2026-08-16. Analysis generated by SEC.co (claude-haiku-4-5).
Affected vendors
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-10001HIGHChrome Sandbox Escape via PerformanceManager Use-After-Free
- CVE-2026-10002HIGHGoogle Chrome PDFium Use-After-Free Vulnerability (CVSS 8.8)
- CVE-2026-10003HIGHChrome Use-After-Free Code Execution Vulnerability Analysis
- CVE-2026-10006HIGHChrome WebAudio Race Condition Remote Code Execution
- CVE-2026-10007HIGHChrome Use-After-Free in SVG Arbitrary Code Execution (CVSS 8.8)
- CVE-2026-10009HIGHChrome Skia Integer Overflow Sandbox Escape – Patch Guidance
- CVE-2026-10012HIGHChrome Skia Use-After-Free Sandbox Escape (v148.0.7778.216)
- CVE-2026-10013HIGHUse-After-Free in Chrome WebCodecs – Patch Guide & Risk Assessment