GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
-
Two unpatched flaws in GeoNetwork, the open-source geospatial metadata catalog, can be linked into an unauthenticated remote code execution (RCE) chain. The software commonly underpins government and agency geoportals, making the risk particularly acute for public-sector infrastructure.
The maintainers addressed both issues in releases 4.4.12 and 4.2.17, shipped on July 8, 2026. Full technical disclosure followed on August 31.
The vulnerability chain allows an attacker with no prior access to execute arbitrary commands on the underlying server. Given GeoNetwork’s typical deployment at the backend of official mapping and environmental data portals, the exposure could escalate into full server compromise if left unpatched.
If you operate an affected instance, consider the following steps:
- Upgrade to GeoNetwork 4.4.12 or 4.2.17 immediately.
- Audit server logs for suspicious requests targeting catalog or metadata endpoints.
- Restrict network access to GeoNetwork administration interfaces until patching is complete.
- Review your deployment for any indicators of post-exploitation activity if the service has been publicly exposed.
Source: The Hacker News
Has your team already patched your GeoNetwork backend, or are you still assessing exposure to this chain?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login