PT-2026-48799 · Git+3 · Geoserver+1

CVE-2025-27511

·

Published

2026-06-11

·

Updated

2026-06-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoServer DB2 DataStore Extension versions prior to 2.27.0
Description An administrator can perform a JNDI attack through a specially crafted DB2 jdbc url, which can lead to Remote Code Execution (RCE). Authenticated users can access the Vector Data Sources page to create a new data store via a db2 jdbc connection. The issue arises from unrestricted connection parameters, allowing the deserialization of untrusted data to achieve RCE. JNDI (Java Naming and Directory Interface) is an API that allows applications to discover and look up data and objects via different naming and directory services.
Recommendations Update to version 2.27.0.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27511
GHSA-G628-R368-6VH7

Affected Products

Geoserver
Org.Geoserver.Extension:Gs-Db2