EXPOSURES › CVE-2026-9182
CVE-2026-9182
MEDIUM
DETAIL
SourceNVD · cve
Published2026-07-06
CVSS5.3
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-9182 ↗
⚡ RCE
SHAME 35/100
rce
ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.
AFFECTED FEDRAMP PRODUCTS · 7
| PRODUCT | STATUS |
|---|---|
| ArcGIS Online (AGO) ESRI |
Authorized |
| ArcGIS Online (AGO) Moderate ESRI |
In Process |
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Esri Managed Cloud Services Advanced Plus ESRI |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |