PT-2026-84459 · Unknown · Geonetwork
CVE-2026-63219
·
Published
2026-09-01
·
Updated
2026-09-07
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GeoNetwork versions prior to 4.4.12
GeoNetwork versions prior to 4.2.17
Description
An unprotected API endpoint used for creating new formatters via file upload allows unauthenticated attackers to upload arbitrary
.xsl or .zip files. This enables unauthorized write access to the server storage by allowing files to be written directly into the GeoNetwork formatter directory.Recommendations
Update GeoNetwork to version 4.4.12 or later.
Update GeoNetwork to version 4.2.17 or later.
Exploit
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geonetwork