laptop and a wrench


There is an improper access control issue in ArcGIS Server.

Last Published: April 18, 2018 ArcGIS GIS Server
Bug ID Number BUG-000113291
SubmittedApril 17, 2018
Last ModifiedMay 31, 2023
Applies toArcGIS GIS Server
Version found10.5.1
Operating SystemWindows OS
Operating System Version2012 R2
Version Fixed10.6.1


Esri has discovered a critical security vulnerability in ArcGIS Server when specially crafted requests are sent to it. This causes improper access control validation to services, which results in secured services and their data being exposed to users who should not otherwise have access.

This issue is present in all currently supported versions of ArcGIS Server. Esri has released patches for versions 10.2.1 through 10.6. The issue has been fixed in ArcGIS Server 10.6.1.


This is a known issue which has been logged by Esri as a defect, BUG-000113291.


Esri strongly recommends installing the relevant patch at the earliest possible opportunity.
All patches can be downloaded from the Esri Support website: ArcGIS Server Improper Access Control Security Patch
Please note that the ArcGIS Server account will be restarted while the patch is applied.
For any questions about this patch and resolving the security vulnerability, please contact Esri Technical Support.

Steps to Reproduce

Bug ID: BUG-000113291


  • ArcGIS GIS Server

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Related Information

Discover more on this topic