GeoNetwork patch release for unauthenticated RCE chain (4.4.12, 4.2.17)
Security Patch Release
Summary
Hide ▲
Show ▼
GeoNetwork shipped 4.4.12 and 4.2.17 to close a vulnerability chain that could lead to unauthenticated remote code execution in exposed deployments. The fix applies to 4.4.x through 4.4.11 and 4.2.x through 4.2.16, making the release relevant for government and agency geoportals and other public-facing catalogs. Administrators were told to upgrade to 4.4.12 or 4.2.17 as soon as possible.
Related Happenings
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Timeline
-
31.08.2026 03:00 1 articles · 2d ago
GeoNetwork discloses chained formatter-upload and XSLT flaws
Initial DisclosureGeoNetwork publishes vulnerability details for a chain built from a missing authorization check on the formatter upload endpoint and an unsafe Saxon XSLT configuration that can run java.lang.Runtime.exec() or java.lang.ProcessBuilder as the GeoNetwork process user. The affected release range is 4.4.x through 4.4.11 and 4.2.x through 4.2.16.
Show sources
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18
-
08.07.2026 03:00 2 articles · 1mo ago
GeoNetwork releases 4.4.12 and 4.2.17 to close unauthenticated RCE chain
Mitigation Patch UpdateGeoNetwork ships versions 4.4.12 and 4.2.17 to fix CVE-2026-63219 and CVE-2026-58400, closing a chain that lets an unauthenticated attacker upload a formatter and trigger code execution through the Saxon XSLT processor. Administrators are told to upgrade to 4.4.12 or 4.2.17 immediately.
Show sources
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18