started · updated
GeoServer zero-day vulnerability triggers mass exploitation probes
A critical unpatched zero-day vulnerability has been disclosed in the open-source geospatial platform GeoServer. The flaw resides in the ‘jsonArrayContains’ functionality, which allows for unauthorized SQL injection. Depending on the specific system configuration—particularly when the service can access a privileged database account—the vulnerability may also enable remote code execution (RCE).
Security firm WatchTowr reported observing hundreds of exploitation probes from a small number of IP addresses within hours of the vulnerability's public disclosure on August 12, 2026. While these initial attempts appear to be reconnaissance, researchers warn that the risk of escalation is high. GeoServer has a history of being targeted at scale, with several previous vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog.
The vulnerability affects various data stores, including PostGIS, Oracle JDBC, and H2. As of the latest reports, no CVE identifier has been assigned and no official patch is currently available, prompting warnings for organizations to check their exposure.