National Cyber Warfare Foundation (NCWF)

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends


0 user ratings
2026-09-02 09:30:14
milo
Blue Team (CND)
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.

The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.

GeoNetwork originated at the United Nations Food and



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.