cve-2026-63219

HIGH CVSS 8.6 nvd
Description

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

Timeline
Published
2026-09-03
Last Modified
2026-09-09
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 8.6 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N 3.9 4.0 security-advisories@github.com
NVD metadata
NVD status
Deferred
Source identifier
security-advisories@github.com
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 8.6,
  "datePublished": "2026-09-03T18:17:22.997",
  "dateUpdated": "2026-09-09T21:09:13.080",
  "description": "GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server.  An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.",
  "id": "CVE-2026-63219",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "core-geonetwork",
            "vendor": "geonetwork",
            "versions": [
              {
                "status": "affected",
                "version": ">= 4.3.0, < 4.4.12"
              },
              {
                "status": "affected",
                "version": "< 4.2.17"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server.  An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17."
      }
    ],
    "id": "CVE-2026-63219",
    "lastModified": "2026-09-09T21:09:13.080",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.0,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-63219",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-03T17:40:15.181226Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-03T18:17:22.997",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://docs.geonetwork-opensource.org/4.2/overview/change-log/version-4.2.17"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://docs.geonetwork-opensource.org/4.4/overview/change-log/version-4.4.12"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/geonetwork/core-geonetwork/pull/9346"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-mh22-prqr-vf42"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  },
  "severity": "HIGH",
  "source": "nvd",
  "title": "GeoNetwork is a catalog application to manage spatially referenced resources"
}
Enrichment data
View JSON API Download JSON