GeoNetwork fixes chained unauthenticated RCE vulnerabilities
π‘οΈ GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution by combining a missing authorization check on the formatter upload endpoint with an unsafe Saxon XSLT configuration. The fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with advisory details published August 31. Vendor-sourced scans found 121 internet-exposed instances across 39 countries, many tied to government or national agencies, and administrators are urged to upgrade or block write methods to the formatter endpoint as an interim mitigation.
