ethiack.com
GeoNetwork Vulnerabilities Enable Unauthenticated RCE Attacks
Article Content
GeoNetwork, an open-source geospatial metadata catalog, has two vulnerabilities that can be exploited to achieve unauthenticated remote code execution (RCE). The flaws, CVE-2026-63219 and CVE-2026-58400, allow attackers to upload malicious formatter files and execute them via the Saxon XSLT processor. The vulnerabilities affect numerous government and agency geoportals, with 121 instances identified across 39 countries. The project released patches in versions 4.4.12 and 4.2.17 on July 8, 2026, and detailed the vulnerabilities on August 31. Security vendor Ethiack reported that 89% of the exposed instances are related to government, military, or national agencies. Administrators are urged to upgrade to the latest versions to mitigate the risk.
Key Points: • Two critical vulnerabilities in GeoNetwork enable unauthenticated RCE. • CVE-2026-63219 allows file uploads without authentication. • Patches were released on July 8, 2026; 121 vulnerable instances identified.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.