Missing Authorization in geoserver - CVE-2025-27505
Published: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the REST API index when handling requests to extension-suffixed REST paths such as rest.html. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can reveal whether certain extensions are installed.