hacker-news · Crawled Sep 2, 2026

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Read original article ↗

AI Summary

Two vulnerabilities in GeoNetwork, an open-source geospatial metadata catalog used by government geoportals, can be chained to achieve unauthenticated remote code execution. CVE-2026-63219 allows unauthenticated attackers to upload arbitrary .xsl or .zip formatter files to the server, while CVE-2026-58400 enables execution of operating system commands via a misconfigured Saxon XSLT processor. The combined exploit chain allows remote code execution without authentication, affecting all 4.4.x releases up to 4.4.11 and 4.2.x releases up to 4.2.16. The project released fixes in versions 4.4.12 and 4.2.17, and recommends immediate upgrades or mitigation via reverse proxy rules to block write methods to the formatter endpoint.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.