CVE-2026-63219

Source
https://cve.org/CVERecord?id=CVE-2026-63219
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63219.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63219
Aliases
  • GHSA-mh22-prqr-vf42
Published
2026-09-03T17:13:01Z
Modified
2026-09-11T03:30:22Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
Unauthenticated file upload via missing authorization on formatter upload endpoint
Details

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary .xsl or .zip formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63219.json"
}
References

Affected packages

Git / github.com/geonetwork/core-geonetwork

Affected ranges

Type
GIT
Repo
https://github.com/geonetwork/core-geonetwork
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.3.0"
        },
        {
            "fixed": "4.4.12"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "4.2.17"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.6.1
2.6.3
2.6.4
3.*
3.0.0RC0
3.2.0
3.4.0
3.4.1
3.4.2
4.*
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.2.0
4.2.1
4.2.10
4.2.11
4.2.13
4.2.14
4.2.15
4.2.16
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
4.4.0
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
Other
start-migration

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63219.json"