HackerFeeds

CyberSecurity News

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

The Hacker News
· September 2, 2026

AI summary

GeoNetwork has fixed two vulnerabilities that can be combined to allow unauthenticated remote code execution on its open-source geospatial metadata catalog. This catalog is used behind many government and agency geoportals. The project released fixed versions 4.4.12 and 4.2.17 on July 8, 2026. Details of the vulnerabilities were published on August 31. GeoNetwork was originally developed at the United Nations Food and Agriculture Organization. The vulnerabilities pose a risk to the security of geoportals that rely on GeoNetwork.

Read the full article at The Hacker Newsthehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.