Vulnerability record · CVE-2025-52465 · published 18 June 2026
CVE-2025-52465: Osgeo geoserver vulnerability
Osgeo · Geoserver
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web interface is either disabled or completely removed are not affected since the vulnerability exists in one of the web pages.
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web interface is either disabled or completely removed are not affected since the vulnerability exists in one of the web pages.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/geoserver/geoserver/pull/8584 | Issue TrackingPatch |
| https://github.com/geoserver/geoserver/security/advisories/GHSA-7qmg-grcp-qf25 | MitigationVendor Advisory |
| https://osgeo-org.atlassian.net/browse/GEOS-11852 | Issue Tracking |
| https://research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild | Not Applicable |
Track CVE-2025-52465 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-52465), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.