GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks
Brief
GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function.
The issue can allow attackers to manipulate database queries via publicly accessible OGC WMS and WFS services and, under dangerous PostgreSQL privilege configurations, potentially execute commands on the database host.
Security researcher @q1uf3ng publicly highlighted the issue on August 12, 2026. Exploitation attempts began within hours, demonstrating that exposed GeoServer instances are already attracting attacker attention.
The flaw affects GeoServer’s use of GeoTools when translating CQL filters into SQL queries for PostGIS-backed data stores.
