PT-2026-82462 · Unknown · Geo Controller

·

CVE-2026-78286

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Geo Controller versions prior to 8.9.9
Description An unauthenticated PHP Object Injection exists in the Geo Controller. This issue could potentially lead to Remote Code Execution (RCE), which is a method allowing an attacker to execute arbitrary commands on the target machine.
Recommendations Update Geo Controller to a version newer than 8.9.8. Restrict access to the system to minimize the risk of exploitation.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78286

Affected Products

Geo Controller