GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution

A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under high-risk configurations. This flaw, detailed on August 14, 2026, affects the GeoTools code used by GeoServer to translate Common Query Language (CQL) filters into SQL queries for PostGIS-backed data stores. Reports indicate that exploitation […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: