Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, cve, code-execution, government, vulnerability-management] ยท confidence: high ยท severity: high ยท affected_sectors: [government, technology] ยท au_impact: true

GeoNetwork Fixes Unauthenticated RCE Chain in Government Geoportal Backends

Summary

Two chainable vulnerabilities in GeoNetwork โ€” the open-source geospatial metadata catalogue that sits behind many government and agency geoportals, including the European INSPIRE geoportal โ€” allow unauthorised remote code execution. Fixes shipped in versions 4.4.12 and 4.2.17 on 8 July, with details published 31 August.

Key Facts

  • Chain: CVE-2026-63219 (CVSS 8.6), a missing-authorisation check on the formatter-upload endpoint that lets an anonymous user write arbitrary .xsl or .zip formatter files, combined with an unsafe transformation engine enabling code execution.
  • Status: No exploitation reported; fixes shipped silently ahead of disclosure.
  • Origin: GeoNetwork originated at the UN Food and Agriculture Organization and is maintained under OSGeo.

Related Pages

Source