discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork vulnerabilities fixed, preventing unauthenticated RCE. 89% of affected deployments are government-related.

By Swati Khandelwal·Sep 2·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Image: thehackernews.com

GeoNetwork, an open-source geospatial metadata catalog, has fixed two vulnerabilities that could allow unauthenticated remote code execution. The fixes are in versions 4.4.12 and 4.2.17.

Why it matters

The fixes are crucial for government and agency geoportals, which are vulnerable to unauthenticated RCE attacks. The vulnerabilities affect 89% of affected deployments.

GeoNetwork is a tool used by governments to manage maps and data. Two flaws were found that could let bad guys run their own code on the tool. The tool's team fixed these flaws in new versions to keep the tool safe.

Analysis

{"

Vulnerability Details and Fixes":"The GeoNetwork project has released fixes for two vulnerabilities that can be chained to achieve unauthenticated remote code execution (RCE). The first flaw, CVE-2026-63219, is a missing authorization check on the formatter upload endpoint. The second flaw, CVE-2026-58400, is an unsafe configuration of the Saxon XSLT processor. The fixes are in versions 4.4.12 and 4.2.17.","

Impact and Exposure":"The vulnerabilities affect 121 internet-exposed GeoNetwork deployments across 39 countries. The vendor Ethiack found that 89% of these deployments are government-, military-, or national-agency-related. The fixes are available in all 4.4.x releases up to 4.4.11 and all 4.2.x releases up to 4.2.16.","

Mitigation and Recommendations":"Administrators can block write methods to the formatter endpoint at the reverse proxy to prevent legitimate formatter uploads. The advisory lists interim rules for Apache httpd and Nginx to restrict access to the formatter endpoint."}

Key points

  • GeoNetwork fixes two vulnerabilities that could allow unauthenticated RCE
  • Fixes are available in versions 4.4.12 and 4.2.17
  • 89% of affected deployments are government-related
  • Administrators can block write methods to the formatter endpoint to prevent legitimate uploads
The Upside

The fixes should prevent bad guys from using the tool to run their own code, which could help keep government data safe.

The Downside

If bad guys find a way to exploit the flaws, they could still use the tool to run their own code, which could cause problems.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityweb-securitygeo-networkunauthenticated-rcegovernment

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 2, 2026

Source

thehackernews.com

Share

Topics

securityweb-securitygeo-networkunauthenticated-rcegovernment

Related

More from this desk

Sep 2·bleepingcomputer.com

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Hackers are exploiting a vulnerability in Sangoma Switchvox VoIP platform, leading to remote code execution and reverse shell deployment.

Sep 2·bleepingcomputer.com

Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens

Hackers exploit JFrog Artifactory flaw to create admin tokens, gaining administrative access. JFrog addresses the issue with new versions.

Sep 2·bleepingcomputer.com

Dropbox accounts breached through Lenovo email verification flaw

Dropbox warns some users that unauthorized party accessed their accounts through Lenovo's email verification flaw. 5,000 accounts were accessed, and hacker viewed and downloaded content from some users.

Communicating Under Pressure: Best Practices for Service Providers

Sep 2·cisa.gov

Communicating Under Pressure: Best Practices for Service Providers

CISA and FBI provide guidance on clear, timely, accurate, and audience-appropriate communications during IT and OT outages, emphasizing clarity, accountability, and transparency.