Generalthehackernews.com·8d ago

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Submitted by @

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and

ORIGINAL REPORTING
The Hacker News
Published 8d ago ago · info@thehackernews.com (The Hacker News)
Read full story at The Hacker News

Original reporting by The Hacker News · info@thehackernews.com (The Hacker News). GridIndex is an aggregation and intelligence layer — full credit to the original publisher.

CONTINUE READING

This page summarizes and tracks coverage of this developing story.

Read full story at The Hacker News
0 views 0 upvotes 0 comments 0 shares

Discussion · 0

Sign in to join the discussion.