BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Two GeoNetwork Flaws Enable Unauthenticated Remote Code Execution

  • Two critical vulnerabilities in GeoNetwork can be chained for unauthenticated remote code execution (RCE), affecting many government geoportals.
  • The flaws exist in versions up to 4.4.11 and 4.2.16; fixes were shipped in versions 4.4.12 and 4.2.17 on July 8, 2026.
  • Over 89% of the 121 internet-exposed deployments fingerprinted across 39 countries are government- or military-related.
  • Administrators can temporarily block write methods to the formatter endpoint at the reverse proxy as an interim mitigation.

Two critical vulnerabilities in the open-source geospatial metadata catalog GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE), potentially compromising government geoportals that rely on the software. Researcher Rafael Castilho from security vendor Ethiack reported the flaws, as detailed in the published research. The first flaw, CVE-2026-63219 (CVSS 8.6), is a missing authorization check that allows anonymous users to upload arbitrary .xsl or .zip formatter files to the server. The second flaw, CVE-2026-58400 (CVSS 9.1), involves an unsafe configuration of the Saxon XSLT processor that can execute operating-system commands. Although the second flaw normally requires high privileges, chaining it with the upload flaw removes that precondition, according to the advisory. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published vulnerability details on August 31, strongly urging all users to upgrade. Ethiack fingerprinted 121 internet-exposed deployments running affected versions across 39 countries, noting that 89% were government-, military-, or national-agency-related. The advisory provides interim rules for Apache httpd and Nginx to block write methods to the formatter endpoint until upgrades are applied. No evidence of exploitation in the wild has been reported as of the disclosure, nor has the flaw been added to CISA’s Known Exploited Vulnerabilities catalog. Meanwhile, the disclosure follows a run of security issues across the wider geospatial stack, including previous GeoServer flaws exploited into botnets and cryptocurrency miners.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SEC proposes first blockchain-era transfer agent rule update

The SEC proposed the first major update to transfer agent rules since the 1980s,...

Strategy CEO defends $80K Bitcoin buy after $60K sale

Strategy CEO Phong Le defended buying Bitcoin near $80,000 after selling in the $60,000...

Hyperliquid Strategies boosts equity facility to $2.5B

Hyperliquid Strategies increased its equity facility with Chardan Capital Markets from $1 billion to...

AI Token Prices Plunge Over 50% as Competition Drives Record Lows

AI token prices have fallen more than 50% since summer, with the LLM Token...

Gary Black: Uber ‘should win easily’ with multiple AV fleets

Ark Invest forecasts Tesla's Cybercab could expand the ride-hailing market by 30 to 60...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading