CVE-2026-76904General

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. Patches are available in versions 33.6, 34.5, and 33.6. No known workaround is available. To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-08-21); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Mentions · 2026-08-23: 1Mentions · 2026-08-24: 1Mentions · 2026-09-19: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-08-23: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-09-19: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 1Technical Details · 2026-09-19: 108-2108-2208-2308-2409-19
Signal classification5 categories
General
120.0%
Disclosure
120.0%
Active Exploitation
120.0%
PoC
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-211
General1
2026-08-221
Disclosure1
2026-08-231
Active Exploitation1
2026-08-241
PoC1
2026-09-191
Patch1
Full discourse5 posts
  • 秋风@q1uf3ng
    General

    That's amazing—this vulnerability was assigned the CVE number CVE-2026-76904. Is this the fastest way to get it fixed in this day and age? It really makes you think. https://t.co/IeYH24B2PS

    Post summary

    The post merely announces the assignment of CVE‑2026‑76904 without providing any technical details, PoC, exploit, or patch information.

    33029128.0K
    3.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-76904 Vendor: GeoTools Product: GeoTools Description: GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: "jsonArrayContains" function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater "jsonArrayContains(<column>, <pointer>, <value>)" function writes "<value>" into generated SQL without escaping. Patches are available in versions 33.6, 34.5, and 33.6. No known workaround is available. To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights. Link: https://github.com/yonliud/cve-2026-76904 #dbugs_vuln

    Post summary

    A Proof of Concept/exploit for CVE-2026-76904 has been released, detailing an SQL injection in GeoTools’ PostGIS jsonArrayContains usage, with patches available in newer releases and mitigation steps suggested.

    0402062.4K
    3.6K followersView on X
  • AgentGG@AgentGG_dev
    Active Exploitation

    Found this GeoServer/GeoTools SQLi (CVE-2026-76904) with AgentGG, reported it privately July 3. Weeks later someone else disclosed it and it was exploited in the wild within hours, 1,500+ instances exposed. Run AgentGG on your code before you ship.

    Post summary

    CVE-2026-76904 is a GeoServer/GeoTools SQL injection that is being actively exploited, with more than 1,500 exposed instances reported within hours of disclosure. The post urges users to scan with AgentGG before shipping.

    00020205
    5 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS
    Patch

    未パッチだったGeoServerのSQLインジェクション、CVE-2026-76904として修正版を公開 — PostGIS向け「jsonArrayContains」の問題、CVSS 9.8 https://cyber.nexsight.co/articles/2026/09/19/geoserver-geotools-jsonarraycontains-cve-2026-76904-patch-2026-09-19/

    Post summary

    The text announces a patched SQL Injection vulnerability (CVE-2026-76904) in GeoServer related to PostGIS jsonArrayContains with CVSS 9.8; a fix version was released but no exploit tools, PoC, or active exploitation are mentioned.

    0000046
    74 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 GeoTools, SQL Injection, #CVE-2026-76904 (Critical) -DC-Aug2026-1786 https://dailycve.com/geotools-sql-injection-cve-2026-76904-critical-dc-aug2026-1786/

    Post summary

    The tweet announces the disclosure of CVE‑2026‑76904 as a critical SQL Injection in GeoTools, linking to a dailycve article that presumably contains further details.

    0000039
    230 followersView on X

Explore more