Skip to main content
QUIETLYTIC
Vulnerability

GeoNetwork Code Injection (CVE-2026-58400)

CVE-2026-58400 is a CVSS 9.1 code injection flaw in GeoNetwork via unsecured XSLT processing, fixed in 4.4.12/4.2.17, reported exploited by VulnCheck.

CVE-2026-58400
Threat Level
CRITICAL
CVSS
9.1
Status
Active Exploitation
Confidence
Medium
Affected Products
GeoNetwork, Core-Geonetwork (before 4.4.12/4.2.17)

CVE-2026-58400 carries a CVSS 3.1 base score of 9.1 against GeoNetwork, an open-source catalog application for managing spatially referenced resources. NVD classifies it as both CWE-94 (Code Injection) and CWE-470 (Unsafe Reflection) and states the flaw is fixed in versions 4.4.12 and 4.2.17. VulnCheck’s KEV feed reports the CVE as exploited, dated September 3, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-58400 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description identifies the root cause precisely: GeoNetwork configures its Saxon XSLT processor, used to render “formatters,” without secure processing (FEATURE_SECURE_PROCESSING) and without disabling Java extension functions (ALLOW_EXTERNAL_FUNCTIONS). With those protections off, NVD states any stylesheet loaded by GeoNetwork can invoke java.lang.Runtime.exec() or java.lang.ProcessBuilder directly, achieving arbitrary command execution as the GeoNetwork process user.

The precondition matters here: NVD explicitly states this requires a user with sufficient privileges to upload a formatter. This is not an unauthenticated flaw by NVD’s own account, and the CVSS vector’s PR:H (high privileges required) component reflects that directly. We note this because a widely circulated third-party headline characterizes this CVE as an “unauthenticated RCE” — our source data follows NVD’s own technical description and CVSS vector rather than that headline, and flags the discrepancy rather than silently adopting either figure.

Evidence and confidence

  • Medium confidence — the CVSS 9.1 score, the vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), the dual CWE-94/CWE-470 classification, the fixed versions (4.4.12 and 4.2.17), and the full Saxon-configuration root cause all trace to NVD alone, corroborated by GeoNetwork’s own linked GitHub security advisory. The exploitation report traces to VulnCheck KEV alone.
  • Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.01187, a 66.3rd percentile score as of our ingestion.

We flag one discrepancy rather than resolve it silently: NVD’s own record states the flaw requires privileges sufficient to upload a formatter (PR:H), while a reference article cited from NVD’s own list characterizes the issue as “unauthenticated.” We report NVD’s technical description and CVSS vector as authoritative, per this publication’s standing rule not to change our figures to match a third-party snippet.

Why this matters

This is a case where the required privilege level materially changes the threat model: an attacker needs an account capable of uploading a formatter, not merely network access to the application, which narrows exposure to insiders, compromised accounts with that specific privilege, or a chained attack that first obtains such an account. That said, once that bar is cleared, the outcome NVD describes — arbitrary OS command execution as the GeoNetwork process user — is as severe as an unauthenticated flaw would be.

GeoNetwork is used by government agencies, research institutions, and other organizations to publish geospatial data catalogs, environments where formatter-upload privileges may be granted more broadly than in a typical commercial application, which is worth factoring into how urgently a given deployment should prioritize the fix.

Frequently Asked Questions

What is CVE-2026-58400? A CVSS 9.1 code injection vulnerability (CWE-94/CWE-470) in GeoNetwork, fixed in versions 4.4.12 and 4.2.17, allowing a user with formatter-upload privileges to achieve arbitrary command execution via an unsecured Saxon XSLT processor.

Is CVE-2026-58400 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 3, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Is this exploitable without authentication? No, per NVD’s own record. NVD states the flaw requires a user with sufficient privileges to upload a formatter, and the CVSS vector reflects high privileges required (PR:H). A third-party report characterizing this as “unauthenticated” conflicts with NVD’s own technical description; we follow NVD.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Versions 4.4.12 and 4.2.17, per NVD and GeoNetwork’s own changelog.


Severity, vector, weakness classification, root cause, and fixed versions sourced from the National Vulnerability Database record for CVE-2026-58400, corroborated by GeoNetwork’s own GitHub security advisory and changelogs for 4.2.17 and 4.4.12. Exploitation status and the September 3, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools