type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, cve, code-execution, government, vulnerability-management] ยท confidence: high ยท severity: high ยท affected_sectors: [government, technology] ยท au_impact: true
GeoNetwork Fixes Unauthenticated RCE Chain in Government Geoportal Backends
Summary
Two chainable vulnerabilities in GeoNetwork โ the open-source geospatial metadata catalogue that sits behind many government and agency geoportals, including the European INSPIRE geoportal โ allow unauthorised remote code execution. Fixes shipped in versions 4.4.12 and 4.2.17 on 8 July, with details published 31 August.
Key Facts
- Chain: CVE-2026-63219 (CVSS 8.6), a missing-authorisation check on the formatter-upload endpoint that lets an anonymous user write arbitrary
.xslor.zipformatter files, combined with an unsafe transformation engine enabling code execution. - Status: No exploitation reported; fixes shipped silently ahead of disclosure.
- Origin: GeoNetwork originated at the UN Food and Agriculture Organization and is maintained under OSGeo.
Related Pages
- Cve 2026 63219 โ chain component CVE (CVSS 8.6)