Arbitrary Command Execution Vulnerability in GeoNetwork by GeoNetwork
CVE-2026-58400
What is CVE-2026-58400?
GeoNetwork, a catalog application designed for managing spatially referenced resources, contains a significant vulnerability in versions below 4.4.12 and 4.2.17, due to improper configuration of the Saxon XSLT processor. This misconfiguration allows for the exploitation of external stylesheet files that can execute arbitrary operating system commands with the same privileges as the GeoNetwork process. Specifically, users with the ability to upload formatters can leverage this flaw by injecting a malicious XSL file that calls Java methods such as java.lang.Runtime.exec() or java.lang.ProcessBuilder, leading to potential unauthorized actions within the operating system. To mitigate this security risk, users are advised to upgrade to the patched versions 4.4.12 and 4.2.17.
Affected Version(s)
core-geonetwork >= 4.3.0, < 4.4.12 < 4.3.0, 4.4.12
core-geonetwork < 4.2.17 < 4.2.17
