← Terug naar overzicht

A critical vulnerability (CVE-2026-63219) was discovered in GeoNetwork, a catalog application for managing spatially referenced resources. The API endpoint for creating new formatters via file upload is completely unprotected, requiring no authentication. An unauthenticated attacker can upload arbitrary .xsl or .zip formatter files to the server, resulting in unauthorized write access to server storage. The vulnerability affects GeoNetwork versions prior to 4.4.12 and 4.2.17. This flaw could potentially be chained with other vulnerabilities to achieve remote code execution, as referenced by The Hacker News article about unauthenticated RCE. Patches have been released in GeoNetwork versions 4.4.12 and 4.2.17. Users are strongly advised to upgrade to the patched versions immediately to mitigate the risk of exploitation.

Affected products

  • GeoNetwork 4.2.x prior to 4.2.17
  • GeoNetwork 4.4.x prior to 4.4.12

Related CVE's

  • CVE-2026-63219

Categories

  • Enterprise Applications
  • Web Technologies
  • Zero-Day Vulnerabilities