< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-02T14:48:02+05:30

GeoNetwork Addresses Unauthenticated RCE Vulnerability in Government Geoportal Backends

GeoNetwork addressed a critical unauthenticated remote code execution (RCE) vulnerability chain affecting government geoportal backends, with fixes released in versions 4.4.12 and 4.2.17. The vulnerabilities (CVE-2026-63219 and CVE-2026-58400) allowed arbitrary file uploads and unsafe XSLT processing, enabling RCE without authentication.

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.

The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.

GeoNetwork originated at the United Nations Food and

Read original article

*** END OF TRANSMISSION ***