← Back to the feed

~/article/geonetwork-fixes-unauthenticated-rce-chain-affecting-government-geoporta-1wd2ul
highSource: The Hacker News

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Topics

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/geonetwork-fixes-unauthenticated-rce-chain-affecting-government-geoporta-1wd2ul