Skip to content
COOEY

EXPOSURES › CVE-2026-13020

CVE-2026-13020

HIGH
DETAIL
SourceNVD · cve Published2026-07-07 CVSS8.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-13020 ↗
SHAME 25/100

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

AFFECTED FEDRAMP PRODUCTS · 7
PRODUCTSTATUS
ArcGIS Online (AGO)
ESRI
Authorized
ArcGIS Online (AGO) Moderate
ESRI
In Process
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Esri Managed Cloud Services Advanced Plus
ESRI
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized