GeoNetwork: unauthenticated RCE chain (CVE-2026-63219 + CVE-2026-58400) on government geoportals
GeoNetwork (OSGeo geospatial metadata catalog used behind many government and agency geoportals, including European INSPIRE backends) published advisories on 31 August 2026 for two flaws that chain to unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6 per The Hacker News citing the project) is a missing authorisation check on the formatter upload endpoint that lets an anonymous attacker write arbitrary .xsl or .zip formatter files. CVE-2026-58400 (CVSS 9.1 per the same reporting) is an unsafe Saxon XSLT configuration in the formatter engine that can call Runtime.exec / ProcessBuilder as the GeoNetwork process user once a malicious stylesheet is loaded. Fixes shipped earlier in 4.4.12 and 4.2.17 (8 July 2026); all 4.4.x through 4.4.11 and 4.2.x through 4.2.16 are affected. Vendor/project mitigations until patch: block write methods to /geonetwork/srv/api/formatters at the reverse proxy. Ethiack (Rafael Castilho) reported the chain and said it fingerprinted 121 internet-exposed affected instances across 39 countries, about 89% government/military/agency-related (exposure estimate, not confirmed compromises). The Hacker News (2 September) found no CISA KEV entry and no public in-wild exploitation reporting at disclosure. Primary advisories: GitHub GHSA-mh22-prqr-vf42 and GHSA-x898-729x-cc3r.
- Product
- GeoNetwork
- Versions
- Affected: 4.4.x ≤ 4.4.11 and 4.2.x ≤ 4.2.16; fixed in 4.4.12 and 4.2.17
- CVSS
- 8.6 (CVE-2026-63219); 9.1 (CVE-2026-58400) — as reported by THN from project advisories
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to 4.4.12 or 4.2.17; until then block POST/PUT/PATCH to formatter upload endpoint
Primary: GeoNetwork GHSA-mh22 (upload) · Vendor: GeoNetwork GHSA-x898 (RCE) · CVE: CVE-2026-63219, CVE-2026-58400 · The Hacker News
