- Two critical vulnerabilities in GeoNetwork can be chained for unauthenticated remote code execution (RCE), affecting many government geoportals.
- The flaws exist in versions up to 4.4.11 and 4.2.16; fixes were shipped in versions 4.4.12 and 4.2.17 on July 8, 2026.
- Over 89% of the 121 internet-exposed deployments fingerprinted across 39 countries are government- or military-related.
- Administrators can temporarily block write methods to the formatter endpoint at the reverse proxy as an interim mitigation.
Two critical vulnerabilities in the open-source geospatial metadata catalog GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE), potentially compromising government geoportals that rely on the software. Researcher Rafael Castilho from security vendor Ethiack reported the flaws, as detailed in the published research. The first flaw, CVE-2026-63219 (CVSS 8.6), is a missing authorization check that allows anonymous users to upload arbitrary .xsl or .zip formatter files to the server. The second flaw, CVE-2026-58400 (CVSS 9.1), involves an unsafe configuration of the Saxon XSLT processor that can execute operating-system commands. Although the second flaw normally requires high privileges, chaining it with the upload flaw removes that precondition, according to the advisory. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published vulnerability details on August 31, strongly urging all users to upgrade. Ethiack fingerprinted 121 internet-exposed deployments running affected versions across 39 countries, noting that 89% were government-, military-, or national-agency-related. The advisory provides interim rules for Apache httpd and Nginx to block write methods to the formatter endpoint until upgrades are applied. No evidence of exploitation in the wild has been reported as of the disclosure, nor has the flaw been added to CISA’s Known Exploited Vulnerabilities catalog. Meanwhile, the disclosure follows a run of security issues across the wider geospatial stack, including previous GeoServer flaws exploited into botnets and cryptocurrency miners.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
