Vulnerability threat dossier

CVE-2026-58400

geonetworkcore-geonetwork

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

VTP deterministic threat36.2of 100 · CVSS excluded

VTP analyst assessment

GeoNetwork formatter XSLT execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factCONFIRMED

Assessment

ENISA lists CVE-2026-58400 as known exploited. GeoNetwork's formatter XSLT processing allowed Java extension functions, so a loaded stylesheet could invoke system commands. Reporting states that this flaw can form an unauthenticated remote-code-execution chain with CVE-2026-63219. Fixes are available in 4.4.12 and 4.2.17.

Why it matters

  • GeoNetwork catalog services can host formatter processing exposed to remote users.
  • Command execution through a malicious stylesheet could give an attacker control of the affected application process.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The available reporting describes a chain; it does not show whether this CVE is exploited alone.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use GeoNetwork before 4.4.12 or 4.2.17, upgrade promptly.

AI baseline history (4)
  1. BASELINE ASSESSED
    GeoNetwork formatter XSLT executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    GeoNetwork formatter processing is known to be exploitedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    GeoNetwork unsafe XSLT code executiongpt-5.6-sol · high
  4. BASELINE ASSESSED
    Pending vulnerability associated with GeoNetwork reportinggpt-5.6-sol · high
Technical severityCRITICALCVSS 9.1 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0166th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-58400ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0002 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

CVE-2025-12768CVE-2026-12663CVE-2026-13086CVE-2026-13380CVE-2026-13381CVE-2026-14540CVE-2026-15630CVE-2026-16675CVE-2026-19313CVE-2026-19315CVE-2026-19318CVE-2026-19471CVE-2026-19472CVE-2026-19949CVE-2026-20212CVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280CVE-2026-38577CVE-2026-42038CVE-2026-57909CVE-2026-57910CVE-2026-58048CVE-2026-58400CVE-2026-59346CVE-2026-59347CVE-2026-63219CVE-2026-64532CVE-2026-64533CVE-2026-6471CVE-2026-67276CVE-2026-67277CVE-2026-67278CVE-2026-67279CVE-2026-67281CVE-2026-67394CVE-2026-6881CVE-2026-73749CVE-2026-78174CVE-2026-80047CVE-2026-84115CVE-2026-84117CVE-2026-84118CVE-2026-84119CVE-2026-84120CVE-2026-84121CVE-2026-84122CVE-2026-84123CVE-2026-84124CVE-2026-84125CVE-2026-84126CVE-2026-84235CVE-2026-84352CVE-2026-84353CVE-2026-84645CVE-2026-84647CVE-2026-84648CVE-2026-84649CVE-2026-84650CVE-2026-84652CVE-2026-84665CVE-2026-84667CVE-2026-84668CVE-2026-84669CVE-2026-84670CVE-2026-84671CVE-2026-84672CVE-2026-84673CVE-2026-85046CVE-2026-86060CVE-2026-86206CVE-2026-86207CVE-2026-86218CVE-2026-9585CVE-2026-9586CVE-2026-9587CVE-2026-9588CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625CVE-2026-9633CVE-2026-9634CVE-2026-9637
Separate evidence group
Original

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and

CVE-2024-36401CVE-2025-58360CVE-2026-58400CVE-2026-63219
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-58400

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-58400
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.2vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.24 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-470, CWE-94
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.