Select to view content in your preferred language

ESRI Enterprise Vulnerability for Tomcat - CVE-2026-29146

186
0
Tuesday
vipulsoni
Regular Contributor

Greetings All,

we have received multiple alerts from Cybersecurity Team for the - CVE-2026-29146, tomcat software present in almost all the Esri Enterprise Products. 11.3 and 11.5 installations of ArcGIS Server and ArcGIS Portal, ArcGIS Data Store. I am unable to find any ESRI Patch or Document stating the vulnerability mitigation patch or the affect of this vulnerability to ESRI Enterprise Software Suite.

 

SoftwareNameSoftwareVersionCveIdEvidencePaths
tomcat9.0.84.0CVE-2026-29146["c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat9.0.84.0CVE-2026-29146["c:\\program files\\arcgis\\datastore\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar","c:\\program files\\arcgis\\portal\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar","c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat10.1.34.0CVE-2026-29146["c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat10.1.34.0CVE-2026-29146["c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat10.1.34.0CVE-2026-29146["c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat10.1.34.0CVE-2026-29146["c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat9.0.84.0CVE-2026-29146["c:\\program files\\arcgis\\datastore\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar","c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
tomcat9.0.62.0CVE-2026-29146["c:\\program files\\arcgis\\datastore\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar","c:\\program files\\arcgis\\server\\framework\\runtime\\tomcat\\bin\\tomcat-juli.jar"]
0 Kudos
0 Replies