PT-2026-48799 · Git+3 · Geoserver+1
CVE-2025-27511
·
Published
2026-06-11
·
Updated
2026-06-24
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoServer DB2 DataStore Extension versions prior to 2.27.0
Description
An administrator can perform a JNDI attack through a specially crafted DB2 jdbc url, which can lead to Remote Code Execution (RCE). Authenticated users can access the Vector Data Sources page to create a new data store via a db2 jdbc connection. The issue arises from unrestricted connection parameters, allowing the deserialization of untrusted data to achieve RCE. JNDI (Java Naming and Directory Interface) is an API that allows applications to discover and look up data and objects via different naming and directory services.
Recommendations
Update to version 2.27.0.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Geoserver
Org.Geoserver.Extension:Gs-Db2