A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under high-risk configurations. This flaw, detailed on August 14, 2026, affects the GeoTools code used by GeoServer to translate Common Query Language (CQL) filters into SQL queries for PostGIS-backed data stores. Reports indicate that exploitation […]
The post GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Divya
Source: gbHackers
Source Link: https://gbhackers.com/geoserver-pre-auth-sql-injection-flaw/