GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 18:17
Updated : 2026-09-09 21:09
NVD link : CVE-2026-63219
Mitre link : CVE-2026-63219
CVE.ORG link : CVE-2026-63219
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
