highOther

Esri Portal for ArcGIS Weak Password Recovery Account Takeover

First seen Jul 10, 2026 · Updated Jul 10, 2026 · CVSS 8.1

account-takeoverauthentication-bypasspassword-recoveryesriarcgisgisweb-application

CVE-2026-13020 is a weak password recovery mechanism vulnerability in Esri Portal for ArcGIS (versions 12.1 and earlier) that allows a remote, unauthenticated attacker to hijack a user's account by manipulating the forgotten-password flow. Organizations running ArcGIS Enterprise on Windows, Linux, or Kubernetes are at risk of unauthorized account access without prior credentials.

Technical Analysis

The vulnerability stems from insufficient validation and predictability weaknesses in the password reset workflow of Esri Portal for ArcGIS, enabling an attacker to reset or take over an account's credentials without proving legitimate ownership. The flaw affects deployments across Windows, Linux, and Kubernetes hosts, and is mitigated by configuring an SMTP/email server for self-service password recovery, which suggests the unpatched behavior may fall back to an insecure or bypassable reset path when no email server is configured. With a CVSS score of 8.1, exploitation requires no authentication and can be performed remotely, making it attractive for opportunistic attackers scanning for exposed ArcGIS portals. Administrators retain the ability to manually reset user passwords, indicating the flaw is isolated to the self-service recovery mechanism rather than core authentication. GIS platforms like ArcGIS are increasingly integrated into geospatial data pipelines and analytics workflows that feed AI agents and RAG systems for location intelligence, so compromised administrator or service accounts could expose API keys, data feeds, or credentials used by autonomous agents querying spatial data services.

Affected Systems

Esri Portal for ArcGIS versions 12.1 and earlier, deployed on Windows, Linux, and Kubernetes; ArcGIS Enterprise installations lacking a properly configured email server for password recovery.

Indicators of Compromise

  • No specific IOCs published; this is a design-level vulnerability rather than a malware campaign. Monitor for anomalous password reset requests, unexpected account ownership changes, and unusual authentication patterns on ArcGIS Portal endpoints.

Remediation Steps

  1. 1

    Upgrade ArcGIS Portal

    Apply the vendor patch or upgrade to a version of Esri Portal for ArcGIS beyond 12.1 once available, following Esri's official security advisory.

  2. 2

    Configure Email Server

    Set up and properly configure an email/SMTP server within ArcGIS Enterprise to enable secure self-service password recovery as recommended by Esri.

  3. 3

    Restrict Self-Service Recovery

    Disable or limit self-service password recovery for privileged/administrator accounts and require manual admin-driven resets instead.

  4. 4

    Monitor Authentication Logs

    Enable logging and alerting on password reset attempts and account ownership changes within ArcGIS Portal to detect exploitation attempts.

  5. 5

    Enforce MFA

    Where supported, enable multi-factor authentication for ArcGIS Portal accounts to reduce the impact of account takeover via password reset abuse.

CVE / Advisory IDs

CVE-2026-13020

Industries Most Exposed

GovernmentUtilitiesGeospatial/Mapping ServicesPublic SectorEngineeringEnvironmental ServicesDefense

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.