GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Read original article ↗AI Summary
Two vulnerabilities in GeoNetwork, an open-source geospatial metadata catalog used by government geoportals, can be chained to achieve unauthenticated remote code execution. CVE-2026-63219 allows unauthenticated attackers to upload arbitrary .xsl or .zip formatter files to the server, while CVE-2026-58400 enables execution of operating system commands via a misconfigured Saxon XSLT processor. The combined exploit chain allows remote code execution without authentication, affecting all 4.4.x releases up to 4.4.11 and 4.2.x releases up to 4.2.16. The project released fixes in versions 4.4.12 and 4.2.17, and recommends immediate upgrades or mitigation via reverse proxy rules to block write methods to the formatter endpoint.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.