URL has been copied successfully!
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.GeoNetwork originated at the United Nations Food and

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link