CVE-2026-54354: MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation

Published Sep 17, 2026
·
Updated

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml<item>type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId input is a numeric literal. The unquoted input is concatenated into the generated PostgreSQL/PostGIS predicate, allowing an unauthenticated remote attacker with access to an affected query endpoint to bypass predicates, enumerate unintended records, perform boolean-based or time-based SQL injection, and increase database load. The issue does not by itself establish database modification capabilities. This issue is fixed in version 8.6.4.

Affected Software

1 affected component
MapServer MapServer<8.6.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MapServer to a version that resolves this vulnerability.

    Fixed in 8.6.4

Event History

Sep 17, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected deployments use MapServer before 8.6.4 with CONNECTIONTYPE POSTGIS and a runtime query endpoint accessible to an attacker. Exposure depends on metadata that causes a filter item to be treated as an Integer, such as gml_<item>_type=Integer.

2

What access does an attacker need to exploit it?

An attacker needs unauthenticated remote access to an affected query endpoint and must be able to supply a CGI qstring or OGC API Features featureId value for the affected numeric filter item. No privileges or user interaction are required.

3

What can exploitation achieve?

An attacker can inject SQL into the generated PostgreSQL/PostGIS predicate to bypass filters, enumerate unintended records, and conduct boolean-based or time-based injection. The issue can also increase database load, but the available information does not establish database modification capability.

4

How can I remediate the issue?

Upgrade MapServer to version 8.6.4, which fixes the issue. Until upgrading, restrict access to affected runtime query endpoints and avoid configurations that classify attacker-controlled filter items as numeric without validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203