GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration
GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration 1. Basic Information Severity: Critical Article Title: Hackers Exploiting Unpatched GeoServer Zero-Day Publisher: SecurityWeek Publication Date: 2026-08-14 Update Date: None Original Article: Original Article Related Sources: None Malware: None Groups: None CVEs:…
A critical SQL injection vulnerability was discovered in GeoServer's jsonArrayContains filter. Within hours of its public disclosure, hundreds of unauthorized attempts were made to exploit this flaw. The GeoServer jsonArrayContains function improperly includes user-provided arguments in database queries, allowing attackers to manipulate data and potentially execute arbitrary code depending on the server's configuration.
While no confirmed remote code execution (RCE) cases have been reported, the vulnerability is particularly dangerous for systems running GeoServer with PostGIS, Oracle, or H2 data stores and without proper security measures. Organizations should immediately apply patches, limit exposure, and monitor for abnormal filter queries, SQL errors, and child processes indicating potential attacks.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.