GeoNetwork Vulnerabilities Enable Unauthenticated RCE Attacks

GeoNetwork Vulnerabilities Enable Unauthenticated RCE Attacks

First seen 2 Sep 2026, 09:44 UTC Thehackernewsgithub.comethiack.com 74.5

Article Content

Browse articles
ThreatCluster

GeoNetwork, an open-source geospatial metadata catalog, has two vulnerabilities that can be exploited to achieve unauthenticated remote code execution (RCE). The flaws, CVE-2026-63219 and CVE-2026-58400, allow attackers to upload malicious formatter files and execute them via the Saxon XSLT processor. The vulnerabilities affect numerous government and agency geoportals, with 121 instances identified across 39 countries. The project released patches in versions 4.4.12 and 4.2.17 on July 8, 2026, and detailed the vulnerabilities on August 31. Security vendor Ethiack reported that 89% of the exposed instances are related to government, military, or national agencies. Administrators are urged to upgrade to the latest versions to mitigate the risk.

Key Points: • Two critical vulnerabilities in GeoNetwork enable unauthenticated RCE. • CVE-2026-63219 allows file uploads without authentication. • Patches were released on July 8, 2026; 121 vulnerable instances identified.

Timeline

2024-07-01
CVE-2024-36401 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-11-25
CVE-2025-58360 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-08
GeoNetwork patches released
Versions 4.4.12 and 4.2.17 were released to fix critical vulnerabilities.
Thehackernews
2026-08-31
Vulnerability details published
GeoNetwork published details of the vulnerabilities CVE-2026-63219 and CVE-2026-58400.
Thehackernews
2026-09-02
Ethiack reports on vulnerabilities
Ethiack identified 121 internet-exposed GeoNetwork deployments running affected versions.
ethiack.com