Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GeoNetwork Resolves Critical RCE Vulnerability Chain

GeoNetwork Resolves Critical RCE Vulnerability Chain

Posted on September 2, 2026 By CWS

GeoNetwork, a prominent open-source geospatial metadata catalog, recently addressed two severe security vulnerabilities that could allow unauthenticated remote code execution (RCE). These issues impact numerous government and agency geoportals worldwide, necessitating immediate attention from administrators.

Details of the Vulnerabilities

On July 8, 2026, GeoNetwork released critical updates in versions 4.4.12 and 4.2.17, with further details disclosed on August 31. These vulnerabilities, identified as CVE-2026-63219 and CVE-2026-58400, involve a missing authorization check and an unsafe configuration in the transformation engine, respectively.

The first flaw, CVE-2026-63219, scored at 8.6 on the CVSS scale, permits unauthorized file uploads to the formatter directory. This issue alone grants write access to server storage without authentication.

Exploitation and Impact

The second flaw, CVE-2026-58400, rated 9.1, involves the Saxon XSLT processor’s unsafe configuration that could execute operating system commands. Although this flaw requires high privileges, when combined with the first, it allows unauthenticated attackers to exploit the system fully.

According to Ethiopian security vendor Ethiack, whose researcher Rafael Castilho discovered these flaws, the vulnerability chain affects GeoNetwork versions starting from 4.0.6. Ethiack identified 121 vulnerable deployments in 39 countries, predominantly involving government and military entities.

Mitigation and Recommendations

GeoNetwork strongly advises upgrading to the patched versions 4.4.12 or 4.2.17 to ensure protection. Until upgrades are applied, administrators should restrict write methods to the formatter endpoint via the reverse proxy to prevent unauthorized uploads.

Interim security measures include configuring Apache httpd to deny POST, PUT, and PATCH requests and limiting Nginx to GET, HEAD, and OPTIONS methods at the /geonetwork/srv/api/formatters location.

The disclosure of these vulnerabilities follows a series of security challenges in the geospatial tech sphere, including past critical flaws in GeoServer that were actively exploited, highlighting the ongoing need for vigilance in geospatial cybersecurity.

Administrators should act promptly to apply these security measures and safeguard their systems against potential exploitation, ensuring the integrity and security of their geospatial data platforms.

The Hacker News Tags:CVE, Cybersecurity, Ethiack, GeoNetwork, Geoportal, GeoServer, Government, INSPIRE, Open Source, OSGeo, RCE, Security, Update, Vulnerability

Post navigation

Previous Post: Remote Access Trojan Hidden in Fake Exodus Wallet Uncovered
Next Post: Chrome and Firefox Updates Fix Critical Security Flaws

Related Posts

Firefox Extensions Exploit Web3 Users to Steal Wallet Data Firefox Extensions Exploit Web3 Users to Steal Wallet Data The Hacker News
Google Integrates Rust DNS Parser in Pixel 10 for Security Google Integrates Rust DNS Parser in Pixel 10 for Security The Hacker News
Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector The Hacker News
Android Malware Poses Threat to Mobile Banking Users Android Malware Poses Threat to Mobile Banking Users The Hacker News
SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw The Hacker News
Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SonicWall Vulnerabilities Under Active Exploit Alert
  • Chrome and Firefox Updates Fix Critical Security Flaws
  • GeoNetwork Resolves Critical RCE Vulnerability Chain
  • Remote Access Trojan Hidden in Fake Exodus Wallet Uncovered
  • AI Aids Researchers in Transferring RCE Exploit Across PLC Models

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SonicWall Vulnerabilities Under Active Exploit Alert
  • Chrome and Firefox Updates Fix Critical Security Flaws
  • GeoNetwork Resolves Critical RCE Vulnerability Chain
  • Remote Access Trojan Hidden in Fake Exodus Wallet Uncovered
  • AI Aids Researchers in Transferring RCE Exploit Across PLC Models

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark