CVE Tools
Back to feed
Patch released GeoNetwork rce OSGeo web-app

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

OSGeo has released updates for GeoNetwork, addressing two vulnerabilities that allow attackers to achieve remote code execution without authentication. The exploit chain combines CVE-2026-63219, a missing authorization check on the formatter upload endpoint, with CVE-2026-58400, an unsafe configuration of the Saxon XSLT processor. These flaws affect versions prior to 4.4.12 and 4.2.17, which were fixed in July 2026.

Because GeoNetwork underpins many government geoportals, including the European INSPIRE portal, this exposure is significant. Security researchers identified over 120 exposed instances worldwide, with the majority belonging to public sector organizations. Administrators should upgrade immediately or block write requests to the formatter endpoint as a temporary mitigation.