PT-2026-49053 · Geoserver · Geoserver

CVE-2025-52465

·

Published

2025-09-02

·

Updated

2026-06-25

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GeoServer versions prior to 2.26.4 GeoServer versions prior to 2.27.3
Description An authenticated administrator with access to the security system can provide arbitrary absolute file paths to the Master Password Dump web page to create files containing the master password in plaintext. This occurs because the software performs minimal validation on the provided java.io.File path. Since there is no default maximum password length, an administrator could include malicious code in the password and dump it into a JSP (JavaServer Pages) file. If the environment allows dynamic deployment and execution of JSP files, such as a default Tomcat installation, this can lead to remote code execution. On Windows systems, this may be used to trigger outbound NTLM (New Technology LAN Manager) requests to a remote server to disclose NTLM hashes or passwords. Additionally, the ability to write files to any location where the process has permissions could result in a denial of service.
Recommendations Update to version 2.26.4. Update to version 2.27.3. Disable or completely remove the web interface to mitigate the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08880
CVE-2025-52465
GHSA-7QMG-GRCP-QF25

Affected Products

Geoserver