The record
Written from the 1 report below. Nothing here is unsourced.
- GeoNetwork, an open-source geospatial metadata catalog used behind many government geoportals, has released patches for two vulnerabilities that can be chained to give unauthenticated attackers remote code execution.
- The first flaw (CVE-2026-63219) allows anonymous users to upload malicious files, and the second (CVE-2026-58400) lets a malicious stylesheet run operating-system commands; together they remove the need for any privileges.
- Fixes shipped on July 8, 2026, in versions 4.4.12 and 4.2.17, and details were published on August 31.
- Ethiack, whose researcher found the flaws, identified 121 internet-exposed vulnerable deployments across 39 countries, mostly government-related, though no confirmed exploitation in the wild has been reported.
What to watch next
- Whether the flaws are added to CISA's Known Exploited Vulnerabilities catalog or public exploitation emerges
- How quickly government and agency operators of exposed GeoNetwork instances upgrade to 4.4.12 or 4.2.17 or apply the reverse-proxy mitigations
- Further security issues in the wider geospatial stack such as GeoServer, which has seen recent actively exploited flaws
Coverage1
1 report
English national1
All filed from India
Named XX · European Union · European INSPIRE geoportal · GeoNetwork · Ethiack · Open Source Geospatial Foundation · Rafael Castilho · United Nations Food and Agriculture Organization
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
