
Unauthenticated RCE Vulnerabilities Patched in GeoNetwork
VulnerabilitiesRemoteCodeExecutionSoftwareUpdatesGeospatialTechnology
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which is used by many government and agency geoportals. Fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with vulnerability details published on August 31, 2026. GeoNetwork originated at the United Nations Food and Agriculture Organization.