GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
GeoNetwork vulnerabilities fixed, preventing unauthenticated RCE. 89% of affected deployments are government-related.
Intelligence analysis by Qwen 2.5 (3B)

GeoNetwork, an open-source geospatial metadata catalog, has fixed two vulnerabilities that could allow unauthenticated remote code execution. The fixes are in versions 4.4.12 and 4.2.17.
GeoNetwork is a tool used by governments to manage maps and data. Two flaws were found that could let bad guys run their own code on the tool. The tool's team fixed these flaws in new versions to keep the tool safe.
Analysis
{"
Vulnerability Details and Fixes":"The GeoNetwork project has released fixes for two vulnerabilities that can be chained to achieve unauthenticated remote code execution (RCE). The first flaw, CVE-2026-63219, is a missing authorization check on the formatter upload endpoint. The second flaw, CVE-2026-58400, is an unsafe configuration of the Saxon XSLT processor. The fixes are in versions 4.4.12 and 4.2.17.","
Impact and Exposure":"The vulnerabilities affect 121 internet-exposed GeoNetwork deployments across 39 countries. The vendor Ethiack found that 89% of these deployments are government-, military-, or national-agency-related. The fixes are available in all 4.4.x releases up to 4.4.11 and all 4.2.x releases up to 4.2.16.","
Mitigation and Recommendations":"Administrators can block write methods to the formatter endpoint at the reverse proxy to prevent legitimate formatter uploads. The advisory lists interim rules for Apache httpd and Nginx to restrict access to the formatter endpoint."}
Key points
- GeoNetwork fixes two vulnerabilities that could allow unauthenticated RCE
- Fixes are available in versions 4.4.12 and 4.2.17
- 89% of affected deployments are government-related
- Administrators can block write methods to the formatter endpoint to prevent legitimate uploads
The fixes should prevent bad guys from using the tool to run their own code, which could help keep government data safe.
If bad guys find a way to exploit the flaws, they could still use the tool to run their own code, which could cause problems.


