Vulnerability threat dossier

CVE-2026-63219

geonetworkcore-geonetwork

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

VTP deterministic threat36.1of 100 · CVSS excluded

VTP analyst assessment

GeoNetwork unauthenticated formatter upload

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factCONFIRMED

Assessment

ENISA lists CVE-2026-63219 as known exploited. GeoNetwork versions before 4.4.12 and 4.2.17 allow unauthenticated uploads of formatter files through the formatter-creation API. An attacker can upload arbitrary XSL or ZIP content, and reporting describes an unauthenticated RCE chain with CVE-2026-58400.

Why it matters

  • An unprotected upload endpoint gives remote attackers a path to place attacker-controlled content on a GeoNetwork server.
  • The paired XSLT-processing flaw can turn uploaded formatter content into code execution.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The public reporting describes the chain and does not identify individual victims or exploitation details.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use GeoNetwork before 4.4.12 or 4.2.17, upgrade promptly.

AI baseline history (4)
  1. BASELINE ASSESSED
    GeoNetwork unauthenticated formatter uploadgpt-5.6-terra · low
  2. BASELINE ASSESSED
    GeoNetwork file upload flaw is known to be exploitedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    GeoNetwork unauthenticated formatter uploadgpt-5.6-sol · high
  4. BASELINE ASSESSED
    Pending vulnerability associated with GeoNetwork reportinggpt-5.6-sol · high
Technical severityHIGHCVSS 8.6 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0039th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-63219ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0002 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

CVE-2025-12768CVE-2026-12663CVE-2026-13086CVE-2026-13380CVE-2026-13381CVE-2026-14540CVE-2026-15630CVE-2026-16675CVE-2026-19313CVE-2026-19315CVE-2026-19318CVE-2026-19471CVE-2026-19472CVE-2026-19949CVE-2026-20212CVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280CVE-2026-38577CVE-2026-42038CVE-2026-57909CVE-2026-57910CVE-2026-58048CVE-2026-58400CVE-2026-59346CVE-2026-59347CVE-2026-63219CVE-2026-64532CVE-2026-64533CVE-2026-6471CVE-2026-67276CVE-2026-67277CVE-2026-67278CVE-2026-67279CVE-2026-67281CVE-2026-67394CVE-2026-6881CVE-2026-73749CVE-2026-78174CVE-2026-80047CVE-2026-84115CVE-2026-84117CVE-2026-84118CVE-2026-84119CVE-2026-84120CVE-2026-84121CVE-2026-84122CVE-2026-84123CVE-2026-84124CVE-2026-84125CVE-2026-84126CVE-2026-84235CVE-2026-84352CVE-2026-84353CVE-2026-84645CVE-2026-84647CVE-2026-84648CVE-2026-84649CVE-2026-84650CVE-2026-84652CVE-2026-84665CVE-2026-84667CVE-2026-84668CVE-2026-84669CVE-2026-84670CVE-2026-84671CVE-2026-84672CVE-2026-84673CVE-2026-85046CVE-2026-86060CVE-2026-86206CVE-2026-86207CVE-2026-86218CVE-2026-9585CVE-2026-9586CVE-2026-9587CVE-2026-9588CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625CVE-2026-9633CVE-2026-9634CVE-2026-9637
Separate evidence group
Original

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and

CVE-2024-36401CVE-2025-58360CVE-2026-58400CVE-2026-63219
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-63219

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-63219
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.1vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.09 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.6 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CWE
CWE-862
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.