thehackernews.com·8d ago
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Submitted by @
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
The Hacker News
Published 8d ago ago · info@thehackernews.com (The Hacker News)
Original reporting by The Hacker News · info@thehackernews.com (The Hacker News). GridIndex is an aggregation and intelligence layer — full credit to the original publisher.
This page summarizes and tracks coverage of this developing story.
Read full story at The Hacker News 0 views 0 upvotes 0 comments 0 shares
Discussion · 0
Sign in to join the discussion.