SQL Injection Vulnerability in MapServer's PostGIS Runtime Filter
CVE-2026-54354

8.2HIGH

Key Information:

Vendor

Mapserver

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54354?

MapServer, a platform for building web-based GIS applications, has a vulnerability in its PostGIS runtime filter. Prior to version 8.6.4, it mishandles user input for certain filter items, treating them as numeric without proper validation. This flaw allows an unauthenticated remote attacker to craft malicious inputs that can be incorporated into PostgreSQL/PostGIS predicates. As a result, the attacker might bypass security predicates, access unintended database records, and potentially introduce SQL injection techniques, increasing the load on the database. While this vulnerability does not permit direct database modifications, it poses significant risks for data integrity and system performance.

Affected Version(s)

MapServer >= 8.4.0, < 8.6.4

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.