Skip to content
COOEY

EXPOSURES › CVE-2026-9182

CVE-2026-9182

MEDIUM
DETAIL
SourceNVD · cve Published2026-07-06 CVSS5.3 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-9182 ↗
⚡ RCE SHAME 35/100 rce

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

AFFECTED FEDRAMP PRODUCTS · 7
PRODUCTSTATUS
ArcGIS Online (AGO)
ESRI
Authorized
ArcGIS Online (AGO) Moderate
ESRI
In Process
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Esri Managed Cloud Services Advanced Plus
ESRI
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized