Esri Portal for ArcGIS Weak Password Recovery Account Takeover
First seen Jul 10, 2026 · Updated Jul 10, 2026 · CVSS 8.1
CVE-2026-13020 is a weak password recovery mechanism vulnerability in Esri Portal for ArcGIS (versions 12.1 and earlier) that allows a remote, unauthenticated attacker to hijack a user's account by manipulating the forgotten-password flow. Organizations running ArcGIS Enterprise on Windows, Linux, or Kubernetes are at risk of unauthorized account access without prior credentials.
Technical Analysis
The vulnerability stems from insufficient validation and predictability weaknesses in the password reset workflow of Esri Portal for ArcGIS, enabling an attacker to reset or take over an account's credentials without proving legitimate ownership. The flaw affects deployments across Windows, Linux, and Kubernetes hosts, and is mitigated by configuring an SMTP/email server for self-service password recovery, which suggests the unpatched behavior may fall back to an insecure or bypassable reset path when no email server is configured. With a CVSS score of 8.1, exploitation requires no authentication and can be performed remotely, making it attractive for opportunistic attackers scanning for exposed ArcGIS portals. Administrators retain the ability to manually reset user passwords, indicating the flaw is isolated to the self-service recovery mechanism rather than core authentication. GIS platforms like ArcGIS are increasingly integrated into geospatial data pipelines and analytics workflows that feed AI agents and RAG systems for location intelligence, so compromised administrator or service accounts could expose API keys, data feeds, or credentials used by autonomous agents querying spatial data services.
Affected Systems
Esri Portal for ArcGIS versions 12.1 and earlier, deployed on Windows, Linux, and Kubernetes; ArcGIS Enterprise installations lacking a properly configured email server for password recovery.
Indicators of Compromise
- No specific IOCs published; this is a design-level vulnerability rather than a malware campaign. Monitor for anomalous password reset requests, unexpected account ownership changes, and unusual authentication patterns on ArcGIS Portal endpoints.
Remediation Steps
- 1
Upgrade ArcGIS Portal
Apply the vendor patch or upgrade to a version of Esri Portal for ArcGIS beyond 12.1 once available, following Esri's official security advisory.
- 2
Configure Email Server
Set up and properly configure an email/SMTP server within ArcGIS Enterprise to enable secure self-service password recovery as recommended by Esri.
- 3
Restrict Self-Service Recovery
Disable or limit self-service password recovery for privileged/administrator accounts and require manual admin-driven resets instead.
- 4
Monitor Authentication Logs
Enable logging and alerting on password reset attempts and account ownership changes within ArcGIS Portal to detect exploitation attempts.
- 5
Enforce MFA
Where supported, enable multi-factor authentication for ArcGIS Portal accounts to reduce the impact of account takeover via password reset abuse.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.