GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Brief
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.
The project shipped fixes in versions 4.
- 12 and 4.
- 17 on July 8, 2026, and published the vulnerability details on August 31.
GeoNetwork originated at the United Nations Food and
