CVE-2026-1446

There is a Cross Site Scripting issue in Esri ArcGIS Pro versions 3.6.0 and earlier. A local attacker could supply malicious strings into ArcGIS Pro which may execute when a specific dialog is opened. This issue is fixed in ArcGIS Pro 3.6.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esri:arcgis_pro:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-26 18:16

Updated : 2026-02-02 13:31


NVD link : CVE-2026-1446

Mitre link : CVE-2026-1446

CVE.ORG link : CVE-2026-1446


JSON object : View

Products Affected

esri

  • arcgis_pro
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')