GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Image: The Hacker News
ad slot · in-content video 16:9
Coverage
More coverage
- Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published…