CVE-2026-63219 – core-geonetwork

CVSS 8.6 IMPORTANT Critical - Same Day Deployment

“An exposed upload path and unsafe XSLT processing can combine into a route from file write to command execution.”

GeoNetwork patched two vulnerabilities affecting formatter handling. CVE-2026-63219 allows an unauthenticated attacker to upload arbitrary .xsl or .zip formatter files into the GeoNetwork formatter directory. It has a CVSS score of 8.6, High severity. CVE-2026-58400 allows uploaded XSLT stylesheets to invoke Java functionality and execute arbitrary operating-system commands as the GeoNetwork process user. It has a CVSS score of 9.1, Critical severity.

Both issues are fixed in GeoNetwork versions 4.4.12 and 4.2.17.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.