Unauthenticated SQL Injection in GeoTools PostGIS DataStore
A critical unauthenticated SQL injection vulnerability (CVE-2026-76904) in the GeoTools library allows remote attackers to execute arbitrary SQL via the jsonArrayContains filter function.
CVE search metadata
CVE search record: CVE-2026-76904. Severity: critical. CVSS: 9.8. EPSS: 0.52%. KEV: no. Product: GeoTools. Brief: Unauthenticated SQL Injection in GeoTools PostGIS DataStore. Brief link: https://feed.craftedsignal.io/briefs/2026-08-geotools-sql-injection/
What's new
- 1. poc_available Aug 26, 12:03 via sploitus
GeoTools, a popular Java library for geospatial data, contains a critical SQL injection vulnerability (CVE-2026-76904) within its PostGIS DataStore implementation. The flaw resides in the jsonArrayContains filter function, which fails to properly sanitize the input value parameter when generating SQL queries for databases running PostGIS 12 or later. By providing malicious input to this function, an unauthenticated attacker can inject arbitrary SQL commands into the backend database. This vulnerability affects multiple versions of the gt-jdbc-postgis package, specifically versions 35.0, 34.0 through 34.4, and 30.5 through 33.5. Impacted organizations are advised to upgrade to the patched versions (35.1, 33.5, or 34.4) immediately. If upgrading is not immediately feasible, the attack surface can be limited by ensuring the database connection pool used by the GeoTools application is configured with the principle of least privilege, specifically restricting write and administrative permissions.
Impact
Successful exploitation allows remote, unauthenticated attackers to execute arbitrary SQL expressions against the underlying database. This potentially results in complete data exfiltration, unauthorized modification of geospatial datasets, and database-level compromise. The vulnerability is highly severe due to its unauthenticated nature and the direct access to database operations.
Recommendation
- Upgrade the gt-jdbc-postgis library to versions 35.1, 33.5, or 34.4 immediately to resolve CVE-2026-76904.
- Review database connection pool configurations and restrict the service account privileges assigned to GeoTools to the minimum required subset of data (SELECT only where possible).
- Enable detailed logging for database queries in the application layer to monitor for anomalous SQL syntax or unexpected execution patterns that may indicate exploitation attempts.
Immediate actions
Upgrade gt-jdbc-postgis to versions 35.1, 33.5, or 34.4
Mitigations
Limit database service account permissions for GeoTools application
CVE-2026-76904