ZeroHour
Product

GeoNetwork

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork patched two chained flaws (CVE-2026-63219, CVE-2026-58400) enabling unauthenticated RCE in government geospatial metadata catalogs.

Two flaws in the open-source GeoNetwork catalog chain into unauthenticated RCE: a missing authorization check on the formatter upload endpoint (CVE-2026-63219, CVSS 8.6) and an unsafe Saxon XSLT processor configuration allowing Java execution (CVE-2026-58400, CVSS 9.1). Fixes shipped in versions 4.4.12 and 4.2.17 on July 8, 2026, with details published August 31. Ethiack fingerprinted 121 internet-exposed vulnerable deployments across 39 countries, 89% tied to government or military agencies. No exploitation in the wild or KEV listing was reported at disclosure.

Related CVEs

  • Actively Exploited XXE in OSGeo GeoServer WMS GetMap Endpoint
    GeoServer, an open source server for sharing and editing geospatial data, is vulnerable to an XML External Entity (XXE) injection flaw (CWE-611) tracked as CVE-2025-58360. The flaw is triggered when an unauthenticated XML request sent to the /geoserver/wms endpoint with operation GetMap is not sufficiently sanitized or restricted, allowing an attacker to define external entities in the request and have the server resolve them, which can lead to disclosure of local files, SSRF to internal services, and potentially further compromise. It carries a CVSS 3.1 score of 9.8 (critical) with high impact on confidentiality, integrity, and availability, and related reporting describes unauthenticated RCE chains affecting government geoportal backends in this software ecosystem. Any organization running GeoServer 2.26.0 up to but not including 2.26.2, or any version before 2.25.6, is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-12-11, and EPSS assigns a 64.9% probability of exploitation within 30 days (99th percentile).
    · OSGeo GeoServer 2.26.0 through versions before 2.26.2, and all versions before 2.25.6; fixed in 2.25.6, 2.26.3, and 2.27.0 KEVlarge
  • Unauthenticated RCE in OSGeo GeoServer via GeoTools XPath Injection
    OSGeo GeoServer ships the GeoTools library, which evaluates feature property names directly as XPath expressions without proper neutralization (CWE-95), so attacker-supplied input is executed as code rather than treated as data. A remote, unauthenticated attacker triggers the flaw by sending specially crafted requests to a GeoServer service, causing the injected expression to be evaluated in the server's context. Successful exploitation results in remote code execution on the host running GeoServer, giving the attacker control over the mapping server and any data or credentials it can reach. Any organization running GeoServer is affected, and the underlying GeoTools flaw also extends to dependent applications such as GeoNetwork, which shipped its own fix for an unauthenticated RCE chain affecting government geoportal backends. The flaw is being actively exploited: it was added to CISA KEV on 2024-07-15, and EPSS assigns a 99.8% probability of exploitation within 30 days.
    · OSGeo GeoServer Multiple releases prior to the vendor-patched builds (fixed in the 2.23.x, 2.24.x and 2.25.x maintenance lines; exact fixed releases per the OSGeo advisory: 2.2 · OSGeo GeoNetwork (bundles the vulnerable GeoTools library) KEV PoC ×3large
  • Arbitrary Command Execution via Saxon XSLT in GeoNetwork Formatters
    GeoNetwork versions before 4.4.12 and before 4.2.17 run the Saxon XSLT processor used to render formatters without secure processing (FEATURE_SECURE_PROCESSING) and without disabling Java extension functions (ALLOW_EXTERNAL_FUNCTIONS), so any stylesheet the application loads can invoke Java methods directly. A user with sufficient privileges to upload a formatter can deliver a malicious .xsl file that calls java.lang.Runtime.exec() or java.lang.ProcessBuilder, achieving arbitrary operating system command execution with the privileges of the GeoNetwork process. An attacker therefore gains code execution on the server (CVSS 9.1, scope-changing, critical), although network reachability requires an account that can upload formatters. All GeoNetwork deployments on the 4.4 branch prior to 4.4.12 and the 4.2 branch prior to 4.2.17 are affected, and related reporting highlights government geoportal backends as a key exposed population. No public proof-of-concept or confirmed in-the-wild exploitation is known (not in CISA KEV; EPSS ~1.2% over 30 days), though related headlines describe a fixed unauthenticated RCE chain affecting government geoportals, suggesting the flaw may be reachable through a longer attack chain.
    · OSGeo (GeoNetwork project) GeoNetwork opensource (4.4 branch) all versions prior to 4.4.12 · OSGeo (GeoNetwork project) GeoNetwork opensource (4.2 branch) all versions prior to 4.2.17moderate
  • Unauthenticated Arbitrary File Write in GeoNetwork Formatter Upload API
    GeoNetwork, the open-source catalog application for managing spatially referenced resources, is affected by a missing-authorization flaw (CWE-862) in the API endpoint used to create new formatters, which leaves its file upload unprotected in versions prior to 4.4.12 and 4.2.17. An unauthenticated attacker with network access to the API can upload arbitrary .xsl or .zip formatter files. This allows the attacker to write arbitrary files into the GeoNetwork formatter directory, an unauthorized write to server storage that the CVSS scores as a high-integrity, scope-changing impact, and related news coverage reports the issue being chained into unauthenticated remote code execution on government geoportal backends. Any deployment running GeoNetwork 4.4.x prior to 4.4.12 or 4.2.x prior to 4.2.17 where the formatter creation endpoint is reachable, particularly internet-exposed geoportals, is affected. No in-the-wild exploitation, public proof-of-concept, or KEV listing is currently known, and EPSS estimates roughly a 0.5% probability of exploitation within 30 days.
    · GeoNetwork (GeoNetwork opensource project) GeoNetwork 4.4.x prior to 4.4.12 · GeoNetwork (GeoNetwork opensource project) GeoNetwork 4.2.x prior to 4.2.17moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.