CVE-2025-52465 - CVE House
Back to Database
Status published High CVE-2025-52465

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

Vulnerability Description

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web interface is either disabled or completely removed are not affected since the vulnerability exists in one of the web pages.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52465

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

org.geoserver.web:gs-web-app, org.geoserver.web:gs-web-sec-core
Vulnerable Versions:
< 2.26.4, >= 2.27.0, < 2.27.3

Timeline

Official Publish: June 18th, 2026
Last Modified: June 24th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)