EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2026-70647
Severity: HIGH
Base Score: 8.6
CVSS Version: 3.1
Vulnerability Description
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Changed
▪
Confidentiality Impact (C): None
▪
Integrity Impact (I): High
▪
Availability Impact (A): None
Affected Vendors & Systems
Vendor
geonetwork
References & Advisory Links
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-mh22-prqr-vf42
- https://github.com/geonetwork/core-geonetwork/pull/9346
- https://docs.geonetwork-opensource.org/4.2/overview/change-log/version-4.2.17
- https://docs.geonetwork-opensource.org/4.4/overview/change-log/version-4.4.12
- https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
GitHub_M
EPSS Probability
0.47
Known Aliases
CVE-2026-63219
Published On
2026-09-03
Last Updated
2026-09-03
Exploited Since
2026-09-02