GeoNetwork fixes vulnerability chain enabling remote command execution

The GeoNetwork project published security advisories concerning unauthenticated formatter uploads and a Saxon XSLT flaw. Versions 4.4.12 and 4.2.17 also address CVE-2026-58400, which has a CVSS score of 9.1.

GeoNetwork vulnerability fixes are available in versions 4.4.12 and 4.2.17. On August 31, 2026, the project published security advisories concerning a chain of flaws that, if successfully exploited, could enable remote command execution with the privileges of the GeoNetwork process. One of the flaws, CVE-2026-58400, has a CVSS score of 9.1.

The fixed releases 4.4.12 and 4.2.17 were published on July 8, 2026. Operators should therefore verify the product branch in use and update to the applicable fixed version.

GeoNetwork vulnerability fixes address Saxon XSLT processing

According to the CVE-2026-58400 security advisory, the flaw allows arbitrary commands to be executed by the GeoNetwork process if an attacker can upload a formatter stylesheet. The issue is related to the configuration of the Saxon XSLT processor.

The RCE flaw itself requires the ability to upload a formatter stylesheet. However, the project also published an advisory concerning unauthenticated formatter uploads. Chaining these two issues could eliminate the need for prior privileges that would otherwise be required to exploit the XSLT flaw.

Unfixed publicly accessible instances could, if both steps are successfully combined, allow remote command execution in the context of the GeoNetwork process. The extent of actually exposed and unupdated deployments is not known.

What administrators should do

  • Verify the version of the deployed GeoNetwork instance.
  • Update branch 4.4 to version 4.4.12 or branch 4.2 to version 4.2.17.
  • Check whether the instance is publicly accessible and allows formatter uploads.
  • Monitor for any additional project guidance on restricting formatter uploads and checking for compromise.

GeoNetwork serves as a catalog of geospatial metadata and is used in spatial data infrastructure initiatives. The combination of anonymous uploads and unsafe XSLT processing increases the urgency of updating.

Active exploitation has not been confirmed so far

Active exploitation of CVE-2026-58400 or the compromise of a specific organization has not been confirmed. The extent of actually exposed and unpatched deployments has also not been independently confirmed.

Further developments will depend mainly on any information about exploitation attempts, the flaw’s inclusion in catalogs of actively exploited vulnerabilities, and statements from operators of public GeoNetwork portals regarding completed updates.

Sources

Verified and updated: 09/02/2026 12:05

Sharing