---
id: CVE-2026-58400
title: GeoNetwork is a catalog application to manage spatially referenced resources
summary: >-
  GeoNetwork is a catalog application to manage spatially referenced resources.
  Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render
  formatters is configured without secure processing
  (`FEATURE_SECURE_PROCESSING`) a…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-470
vendor: geonetwork
product: core-geonetwork
affected:
  - 'core-geonetwork >= 4.3.0, < 4.4.12'
  - core-geonetwork < 4.2.17
published: '2026-09-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:09:13.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58400'
references:
  - url: >-
      https://docs.geonetwork-opensource.org/4.2/overview/change-log/version-4.2.17
    label: security-advisories@github.com
  - url: >-
      https://docs.geonetwork-opensource.org/4.4/overview/change-log/version-4.4.12
    label: security-advisories@github.com
  - url: >-
      https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-x898-729x-cc3r
    label: security-advisories@github.com
  - url: >-
      https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-03T17:49:43.605439Z'
ingestedAt: '2026-09-11T02:23:18.706Z'
epss: 0.01187
epssPercentile: 0.66506
---

## Overview

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke
`java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
