Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GeoNetwork Resolves Critical RCE Vulnerability Chain

GeoNetwork Resolves Critical RCE Vulnerability Chain

Posted on September 2, 2026 By CWS

GeoNetwork, a prominent open-source geospatial metadata catalog, recently addressed two severe security vulnerabilities that could allow unauthenticated remote code execution (RCE). These issues impact numerous government and agency geoportals worldwide, necessitating immediate attention from administrators.

Details of the Vulnerabilities

On July 8, 2026, GeoNetwork released critical updates in versions 4.4.12 and 4.2.17, with further details disclosed on August 31. These vulnerabilities, identified as CVE-2026-63219 and CVE-2026-58400, involve a missing authorization check and an unsafe configuration in the transformation engine, respectively.

The first flaw, CVE-2026-63219, scored at 8.6 on the CVSS scale, permits unauthorized file uploads to the formatter directory. This issue alone grants write access to server storage without authentication.

Exploitation and Impact

The second flaw, CVE-2026-58400, rated 9.1, involves the Saxon XSLT processor’s unsafe configuration that could execute operating system commands. Although this flaw requires high privileges, when combined with the first, it allows unauthenticated attackers to exploit the system fully.

According to Ethiopian security vendor Ethiack, whose researcher Rafael Castilho discovered these flaws, the vulnerability chain affects GeoNetwork versions starting from 4.0.6. Ethiack identified 121 vulnerable deployments in 39 countries, predominantly involving government and military entities.

Mitigation and Recommendations

GeoNetwork strongly advises upgrading to the patched versions 4.4.12 or 4.2.17 to ensure protection. Until upgrades are applied, administrators should restrict write methods to the formatter endpoint via the reverse proxy to prevent unauthorized uploads.

Interim security measures include configuring Apache httpd to deny POST, PUT, and PATCH requests and limiting Nginx to GET, HEAD, and OPTIONS methods at the /geonetwork/srv/api/formatters location.

The disclosure of these vulnerabilities follows a series of security challenges in the geospatial tech sphere, including past critical flaws in GeoServer that were actively exploited, highlighting the ongoing need for vigilance in geospatial cybersecurity.

Administrators should act promptly to apply these security measures and safeguard their systems against potential exploitation, ensuring the integrity and security of their geospatial data platforms.

The Hacker News Tags:CVE, Cybersecurity, Ethiack, GeoNetwork, Geoportal, GeoServer, Government, INSPIRE, Open Source, OSGeo, RCE, Security, Update, Vulnerability

Post navigation

Previous Post: Remote Access Trojan Hidden in Fake Exodus Wallet Uncovered
Next Post: Chrome and Firefox Updates Fix Critical Security Flaws

Related Posts

Enterprise AI Usage: Risks Centralized Among Power Users Enterprise AI Usage: Risks Centralized Among Power Users The Hacker News
Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution The Hacker News
Security Flaw in Claude for Chrome Allows Unauthorized Access Security Flaw in Claude for Chrome Allows Unauthorized Access The Hacker News
Android 17 Enhances Security by Limiting Accessibility API Access Android 17 Enhances Security by Limiting Accessibility API Access The Hacker News
What is Identity Dark Matter? What is Identity Dark Matter? The Hacker News
BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark