⤷ Title: GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 04:35:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #exploited in the wild #GeoServer #GeoTools #jsonArrayContains #proof_of_concept #RondoDox #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 04:35:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #exploited in the wild #GeoServer #GeoTools #jsonArrayContains #proof_of_concept #RondoDox #sql injection
Daily CyberSecurity
GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
TL;DR A GeoServer unauthenticated SQL injection flaw is under active attack. It lives in the jsonArrayContains filter function against PostGIS layers. Attackers began probing within hours of publi…