CVE-2026-9181
published 2026-07-06CVE-2026-9181: Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.22%
67.3th percentile
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| esri | arcgis_server | <= 12.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Esri ArcGIS Server up to 12.0 Path path traversal
vuldb·2026-07-06·CVSS 9.8
CVE-2026-9181 [CRITICAL] Esri ArcGIS Server up to 12.0 Path path traversal
A vulnerability identified as problematic has been detected in Esri ArcGIS Server up to 12.0. Affected by this vulnerability is an unknown functionality of the component Path Handler. Performing a manipulation results in path traversal.
This vulnerability is reported as CVE-2026-9181. The attack is possible to be carried out remotely. No exploit exists.
GHSA
ArcGIS Server contains a directory traversal vulnerability.
ghsa_unreviewed·2026-07-06
CVE-2026-9181 [CRITICAL] CWE-22 ArcGIS Server contains a directory traversal vulnerability.
ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior.
No detection rules found.
No public exploits indexed.
2026-07-06
Published