In GeoNetwork found four vulnerabilities to capture servers of state geoportals

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
874
Deposit
0$
Four GeoNetwork vulnerabilities have turned a popular geospatial catalog into a potential entry point into the internal networks of government organizations. Etiack specialists found 121 installations of vulnerable versions in 39 countries and regions, with 89% of servers owned by state, military or national structures.

GeoNetwork is an open catalog of geospatial data that helps to publish, search and systematize data about maps and data sets. The project appeared in 2001 at the UN Food and Agriculture Organization, and later passed under the management of the OSGeo community. The platform is widely used by state geoportals, research institutions and environmental services.

The most dangerous chain is formed by two separate errors. The first, CVE-2026-63219 with a score of 8.6 points, left without checking the authorization of the API to download the formatters. An anonymous user could send an arbitrary XSL or ZIP file to the server. The error came after the corresponding API was processed in GeoNetwork 4.0.6, when the developers missed the rights check for one of the methods.

The second gap, CVE-2026-58400 with a score of 9.1 points, is associated with the XSLT Saxon handler. GeoNetwork allowed downloaded stylesheets to access Java features, including system command launch tools. By linking two vulnerabilities that attacked without an account could download a malicious XSLT file, call its processing through a public directory record, and execute commands with GeoNetwork process rights. Etiack demonstrated a chain on version 4.4.11 with the return command shell.


Another problem, CVE-2026-55864, allows an anonymous user to get GeoNetwork to access arbitrary addresses on behalf of the server. Such SSRF vulnerability opens the way to the nodes of internal networks that are not directly accessible from the Internet. If an internal resource returns XML, the attacker can also receive the contents of the response.

The fourth vulnerability, CVE-2026-57582 with a score of 8.2, is a reflected cross-site scripting. A specially prepared link allows JavaScript to be executed in the context of GeoNetwork after the victim goes. When attacked by an administrator, malicious code accesses his session and can perform actions with the appropriate privileges.

Etiack has found vulnerable servers primarily in Europe. The European and international structures of the system accounted for 77.7% of the found installations. The specialists notified the owners of all the detected servers and handed over the temporary recommendations even before the details were publicly disclosed.

GeoNetwork uncovered four vulnerabilities on August 31. The fixes are already included in versions 4.4.12 and 4.2.17, released on July 8. Developers recommend switching to a supported branch as older versions 3.x and 4.0.x no longer receive security patches.
 
Top Bottom