Arbitrary Command Execution Vulnerability in GeoNetwork by GeoNetwork
CVE-2026-58400

9.1CRITICAL

Key Information:

Vendor

Geonetwork

Vendor
CVE Published:
3 September 2026

What is CVE-2026-58400?

GeoNetwork, a catalog application designed for managing spatially referenced resources, contains a significant vulnerability in versions below 4.4.12 and 4.2.17, due to improper configuration of the Saxon XSLT processor. This misconfiguration allows for the exploitation of external stylesheet files that can execute arbitrary operating system commands with the same privileges as the GeoNetwork process. Specifically, users with the ability to upload formatters can leverage this flaw by injecting a malicious XSL file that calls Java methods such as java.lang.Runtime.exec() or java.lang.ProcessBuilder, leading to potential unauthorized actions within the operating system. To mitigate this security risk, users are advised to upgrade to the patched versions 4.4.12 and 4.2.17.

Affected Version(s)

core-geonetwork >= 4.3.0, < 4.4.12 < 4.3.0, 4.4.12

core-geonetwork < 4.2.17 < 4.2.17

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.