CVE-2026-63219 carries a CVSS 3.1 base score of 8.6 against GeoNetwork opensource, a catalog application for managing spatially referenced resources. NVD classifies it as CWE-862 (Missing Authorization) and states the flaw is patched in versions 4.4.12 and 4.2.17. VulnCheck’s KEV feed reports the CVE as exploited, dated September 3, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-63219 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states GeoNetwork’s API endpoint for creating a new “formatter” via file upload is unprotected, allowing an unauthenticated attacker to upload arbitrary .xsl or .zip formatter files. NVD frames the direct consequence conservatively — “unauthorized write access to server storage” — without itself stating that this leads to code execution. A referenced thehackernews.com article, cited in NVD’s own record, characterizes the combined issue as an “unauthenticated RCE,” a stronger claim than NVD’s own description makes on its own. We report both framings rather than picking one: this record documents the file-write primitive as NVD describes it, and readers should treat the RCE characterization as coming from third-party reporting layered on top of NVD’s more conservative technical description.
Notably, this vulnerability shares its September 3, 2026 catalog date and its GeoNetwork target with CVE-2026-58400 (covered separately in our earlier reporting on the GeoNetwork XSLT code injection flaw) — the unprotected upload endpoint this CVE documents is the same formatter-upload feature that CVE-2026-58400’s XSLT code injection is triggered through. Together, the two CVEs describe complementary halves of the same attack chain: this one is the missing-authorization step that lets an attacker plant a malicious formatter file in the first place.
Evidence and confidence
- Medium confidence — the CVSS 8.6 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N), the CWE-862 classification, and the fixed versions all trace to NVD alone in our current ingestion, corroborated by GeoNetwork’s own linked GitHub security advisory and fix pull request. The exploitation report traces to VulnCheck KEV alone. - Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00466, a 39.3rd percentile score as of our ingestion.
- Framing discrepancy — NVD’s own description states “unauthorized write access to server storage” without asserting code execution; a third-party report NVD itself links characterizes the combined issue as unauthenticated RCE. We report this discrepancy rather than resolving it.
Why this matters
Missing-authorization flaws on file-upload endpoints are frequently the quiet first link in a longer attack chain, and this one is a documented case of exactly that pattern: on its own, NVD describes it as unauthorized file-write access, but combined with the separately tracked XSLT code-injection flaw in the same formatter-processing feature (CVE-2026-58400), the pair together plausibly deliver the fuller unauthenticated remote code execution outcome the third-party report describes. Organizations running GeoNetwork should patch against both CVEs together rather than treating either as sufficient on its own.
Frequently Asked Questions
What is CVE-2026-63219? A CVSS 8.6 missing-authorization vulnerability (CWE-862) in GeoNetwork opensource before versions 4.4.12 and 4.2.17, allowing unauthenticated attackers to upload arbitrary formatter files to the server.
Is CVE-2026-63219 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 3, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Is this the same as the GeoNetwork RCE our site covered before? It’s related but distinct. This CVE (CVE-2026-63219) documents the unauthenticated file-upload authorization gap; our earlier coverage of CVE-2026-58400 documents a separate XSLT code-injection flaw in the same formatter feature. Third-party reporting treats the pair as forming a combined unauthenticated RCE chain.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which versions fix this? Versions 4.4.12 and 4.2.17, per NVD and GeoNetwork’s own changelog.
Severity, vector, weakness classification, and fixed versions sourced from the National Vulnerability Database record for CVE-2026-63219, corroborated by GeoNetwork’s own GitHub security advisory and fix pull request. Combined-impact characterization reported by The Hacker News, cited from NVD’s own reference list. Exploitation status and the September 3, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.