CVE-2026-63219
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Summary
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary .xsl or .zip formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| geonetwork | core-geonetwork | >= 4.3.0, < 4.4.12 | affected |
| geonetwork | core-geonetwork | < 4.2.17 | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-mh22-prqr-vf42
- https://github.com/geonetwork/core-geonetwork/pull/9346
- https://docs.geonetwork-opensource.org/4.2/overview/change-log/version-4.2.17
- https://docs.geonetwork-opensource.org/4.4/overview/change-log/version-4.4.12
- https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.