CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5541

As cited

Copy frozen at (site build).

vulnerabilities

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two chained vulnerabilities in GeoNetwork, an open-source geospatial metadata catalog used by government agencies, allow unauthenticated attackers to execute arbitrary code. The project released patches in versions 4.4.12 and 4.2.17 on July 8, 2026, with public disclosure following on August 31.

Why it matters: Government agencies and organizations operating geoportals built on GeoNetwork face immediate risk of compromise if they have not upgraded; patch deployment is critical.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork released patches for two vulnerabilities that can be chained to enable unauthenticated remote code execution on the open-source geospatial metadata catalog. Fixed versions 4.4.12 and 4.2.17 shipped on July 8, 2026, with vulnerability details disclosed on August 31. The software underpins geoportal backends across government and agency deployments.

Why it matters: Government and agency practitioners running GeoNetwork should upgrade to versions 4.4.12 or 4.2.17 to block unauthenticated RCE exploits targeting their geospatial infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary