GeoNetwork unauthenticated RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
GeoNetwork's 4.4.x through 4.4.11 and 4.2.x through 4.2.16 releases now have a chained unauthenticated RCE flaw that can affect government geoportal backends. The issue combines CVE-2026-63219 and CVE-2026-58400 to let an anonymous attacker upload a malicious formatter and trigger command execution through Saxon XSLT. The project shipped fixes in 4.4.12 and 4.2.17 and urged users to upgrade quickly. No public exploitation in the wild was reported at disclosure.
Related Happenings
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
02.09.2026 03:00 1 articles · 11h ago
GeoNetwork ships fixes for chained unauthenticated RCE flaws
Mitigation Patch UpdateGeoNetwork released versions 4.4.12 and 4.2.17 to fix CVE-2026-63219, a missing authorization check on the formatter upload endpoint, and CVE-2026-58400, an unsafe Saxon XSLT configuration that can be chained with the upload flaw to let an unauthenticated attacker upload a malicious formatter and trigger operating-system command execution through a public record request.
Show sources
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18
-
02.09.2026 03:00 2 articles · 11h ago
GeoNetwork publishes details on CVE-2026-63219 and CVE-2026-58400
Initial DisclosureGeoNetwork published details for the chained CVE-2026-63219 and CVE-2026-58400 flaws. Ethiack, whose researcher Rafael Castilho reported the issues, said the chain was reachable starting with version 4.0.6 after the formatter endpoint was refactored and the authorization line was dropped, and it fingerprinted 121 internet-exposed GeoNetwork deployments across 39 countries, with 89 percent tied to government-, military-, or national-agency-related environments; no public exploitation in the wild was reported as of disclosure.
Show sources
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — thehackernews.com — 02.09.2026 12:18