GeoNetwork Remote Code Execution via Unsafe XSLT Processor Configuration

Release Date: 3rd September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and geospatial/GIS teams that deploy or operate GeoNetwork as a metadata catalog or spatial data infrastructure (SDI) platform, including government geoportal backends. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-58400 is a critical remote code execution vulnerability in GeoNetwork, an open-source geospatial metadata catalog maintained under the OSGeo Foundation and widely used to power Spatial Data Infrastructure (SDI) deployments and government geoportals worldwide - the reporting researchers’ own internet-wide scan fingerprinted 121 internet-exposed instances across 39 countries, 89% of which were government, military, or national-agency deployments.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-58400
  2. https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-x898-729x-cc3r