CVE-2026-63219 – core-geonetwork
CVSS 8.6
IMPORTANT
Critical - Same Day Deployment
“An exposed upload path and unsafe XSLT processing can combine into a route from file write to command execution.”
GeoNetwork patched two vulnerabilities affecting formatter handling. CVE-2026-63219 allows an unauthenticated attacker to upload arbitrary .xsl or .zip formatter files into the GeoNetwork formatter directory. It has a CVSS score of 8.6, High severity. CVE-2026-58400 allows uploaded XSLT stylesheets to invoke Java functionality and execute arbitrary operating-system commands as the GeoNetwork process user. It has a CVSS score of 9.1, Critical severity.
Both issues are fixed in GeoNetwork versions 4.4.12 and 4.2.17.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-862
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.