GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Overview
GeoNetwork has addressed two vulnerabilities that could allow attackers to execute remote code without authentication on its geospatial metadata catalog, commonly used by government and agency geoportals. The vulnerabilities were discovered and fixed in versions 4.4.12 and 4.2.17, released on July 8, 2026. This is significant because it exposes systems that rely on GeoNetwork to potential exploitation, which could lead to unauthorized access or control over sensitive data. The details of these vulnerabilities were made public on August 31, 2026, prompting users to update their systems to safeguard against possible attacks. Government agencies and organizations using GeoNetwork should prioritize applying these updates to prevent any exploitation of the vulnerabilities.
Key Takeaways
- Affected Systems: GeoNetwork versions prior to 4.4.12 and 4.2.17
- Action Required: Update to GeoNetwork versions 4.
- Timeline: Disclosed on August 31, 2026
Original Article Summary
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
Impact
GeoNetwork versions prior to 4.4.12 and 4.2.17
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on August 31, 2026
Remediation
Update to GeoNetwork versions 4.4.12 or 4.2.17
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update, RCE.