discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork vulnerabilities fixed, preventing unauthenticated RCE. 89% of affected deployments are government-related.

By Swati Khandelwal·Sep 2·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Image: thehackernews.com

GeoNetwork, an open-source geospatial metadata catalog, has fixed two vulnerabilities that could allow unauthenticated remote code execution. The fixes are in versions 4.4.12 and 4.2.17.

Why it matters

The fixes are crucial for government and agency geoportals, which are vulnerable to unauthenticated RCE attacks. The vulnerabilities affect 89% of affected deployments.

GeoNetwork is a tool used by governments to manage maps and data. Two flaws were found that could let bad guys run their own code on the tool. The tool's team fixed these flaws in new versions to keep the tool safe.

Analysis

{"

Vulnerability Details and Fixes":"The GeoNetwork project has released fixes for two vulnerabilities that can be chained to achieve unauthenticated remote code execution (RCE). The first flaw, CVE-2026-63219, is a missing authorization check on the formatter upload endpoint. The second flaw, CVE-2026-58400, is an unsafe configuration of the Saxon XSLT processor. The fixes are in versions 4.4.12 and 4.2.17.","

Impact and Exposure":"The vulnerabilities affect 121 internet-exposed GeoNetwork deployments across 39 countries. The vendor Ethiack found that 89% of these deployments are government-, military-, or national-agency-related. The fixes are available in all 4.4.x releases up to 4.4.11 and all 4.2.x releases up to 4.2.16.","

Mitigation and Recommendations":"Administrators can block write methods to the formatter endpoint at the reverse proxy to prevent legitimate formatter uploads. The advisory lists interim rules for Apache httpd and Nginx to restrict access to the formatter endpoint."}

Key points

  • GeoNetwork fixes two vulnerabilities that could allow unauthenticated RCE
  • Fixes are available in versions 4.4.12 and 4.2.17
  • 89% of affected deployments are government-related
  • Administrators can block write methods to the formatter endpoint to prevent legitimate uploads
The Upside

The fixes should prevent bad guys from using the tool to run their own code, which could help keep government data safe.

The Downside

If bad guys find a way to exploit the flaws, they could still use the tool to run their own code, which could cause problems.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityweb-securitygeo-networkunauthenticated-rcegovernment

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 2, 2026

Source

thehackernews.com

Share

Topics

securityweb-securitygeo-networkunauthenticated-rcegovernment

Related

More from this desk

Sep 4·thehackernews.com

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign using invisible Unicode characters to bypass email filters.

Sep 4·bleepingcomputer.com

CrowdStrike 'FalconFlank' Zero-Day Exploit Grants SYSTEM Privileges

CrowdStrike released a zero-day exploit named 'FalconFlank' that allows attackers to escalate privileges on up-to-date Windows systems.

Sep 4·bleepingcomputer.com

Exchange Online outage causes email delays, 'Server busy' errors

Microsoft working to resolve Exchange Online outage causing email delays and 'Server busy' errors. Incident first acknowledged at 02:19 AM EDT, impacting users attempting to send and receive email from external domains.

Sep 4·schneier.com

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Researchers found 120 unregistered code packages or domain names in vendor documentation, leading to unauthorized code execution on corporate networks.