arcgis_server vulnerabilities
CVEs whose affected-version data names the arcgis_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-2813Medium· 4.7ArcGIS Server contains an input validation weakness in the login redirection workflow
ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redir…
▾ Sunlitesri · arcgis_serverEPSS 0.30%via NVD
CVE-2026-2812Medium· 5.3ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may re…
▾ Sunlitesri · arcgis_serverEPSS 0.36%via NVD