PT-2026-49053 · Geoserver · Geoserver
CVE-2025-52465
·
Published
2025-09-02
·
Updated
2026-06-25
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GeoServer versions prior to 2.26.4
GeoServer versions prior to 2.27.3
Description
An authenticated administrator with access to the security system can provide arbitrary absolute file paths to the Master Password Dump web page to create files containing the master password in plaintext. This occurs because the software performs minimal validation on the provided
java.io.File path. Since there is no default maximum password length, an administrator could include malicious code in the password and dump it into a JSP (JavaServer Pages) file. If the environment allows dynamic deployment and execution of JSP files, such as a default Tomcat installation, this can lead to remote code execution. On Windows systems, this may be used to trigger outbound NTLM (New Technology LAN Manager) requests to a remote server to disclose NTLM hashes or passwords. Additionally, the ability to write files to any location where the process has permissions could result in a denial of service.Recommendations
Update to version 2.26.4.
Update to version 2.27.3.
Disable or completely remove the web interface to mitigate the risk.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geoserver