ethiack.com
GeoNetwork Vulnerabilities Enable Unauthenticated RCE in Government Systems
Article Content
GeoNetwork, an open-source geospatial metadata catalog, has critical vulnerabilities allowing unauthenticated remote code execution (RCE). Two key CVEs, CVE-2026-63219 and CVE-2026-58400, can be chained to exploit the system. The first flaw allows unauthenticated file uploads to the formatter directory, while the second flaw involves an unsafe configuration of the Saxon XSLT processor. These vulnerabilities affect numerous government and agency geoportals, with 121 exposed deployments identified across 39 countries. The project released patches in versions 4.4.12 and 4.2.17 on July 8, 2026. Security vendor Ethiack reported that 89% of the exposed instances are related to government, military, or national agencies. Administrators are urged to update to the latest versions to mitigate risks. Until then, blocking write access to the vulnerable endpoint is recommended.
Key Points: • Two CVEs allow unauthenticated RCE in GeoNetwork systems. • 121 vulnerable deployments identified, primarily in government sectors. • Patches released; immediate updates are strongly recommended.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.