Unprotected File Upload Vulnerability in GeoNetwork by GeoNetwork
CVE-2026-63219

8.6HIGH

Key Information:

Vendor

Geonetwork

Vendor
CVE Published:
3 September 2026

What is CVE-2026-63219?

CVE-2026-63219 is a significant vulnerability identified in GeoNetwork, an open-source catalog application designed for managing spatially referenced resources. This vulnerability arises from an unprotected API endpoint that allows unauthenticated users to upload arbitrary files, specifically .xsl or .zip formatters, to the server. The failure to restrict file uploads means that an attacker can exploit this weakness to write unauthorized files directly into the GeoNetwork formatter directory, which constitutes unauthorized access to server storage. Such an exploit can compromise the integrity and confidentiality of the system, allowing malicious actors to manipulate or disrupt the normal operations of organizations utilizing GeoNetwork for resource management. The vulnerability has been addressed in updates to GeoNetwork, with patches available in versions 4.4.12 and 4.2.17.

Potential impact of CVE-2026-63219

  1. Unauthorized File Uploads: The lack of protection on the file upload API can lead to arbitrary file uploads, allowing attackers to place malicious files on the server. This can result in the hosting of malware that could compromise the entire system.

  2. Compromise of Server Storage: By gaining write access to the server's formatter directory, attackers could manipulate data and configurations, leading to further vulnerabilities and potential data breaches.

  3. Impact on Service Integrity: The capability for unauthenticated users to upload files can disrupt normal service operations, resulting in service outages or degraded performance due to malicious activity or unintended consequences from uploaded files.

Affected Version(s)

core-geonetwork >= 4.3.0, < 4.4.12 < 4.3.0, 4.4.12

core-geonetwork < 4.2.17 < 4.2.17

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.