CVE Tools
Back to feed
Patch released ArcGIS Server web-app Esri rce

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

The Hacker News·By The Hacker News··15 min read
CVE Tools coverage

A critical security flaw in Esri ArcGIS Server 12.0 and earlier versions has been patched following reports of potential unauthenticated file access. The vulnerability, tracked as CVE-2026-9181 with a CVSS score of 9.8/7.5, allowed attackers to access sensitive files by sending specially crafted path parameters. This flaw resided in the REST Uploads resource due to insufficient validation of inputs, enabling directory traversal attacks. Horizon3.ai highlighted the risk, noting that no authentication was required to exploit it. Users are strongly advised to update to the latest version to mitigate exposure.