CRITICAL 9.1 CVE-2026-58400 Published 3 Sept 2026

GeoNetwork XSLT Processor Command Execution

Worried this affects one of your servers?

GeoNetwork, a catalog application for managing spatially referenced resources, is affected.

Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used for rendering formatters is misconfigured, allowing arbitrary command execution via Java extension functions.

An attacker with sufficient privileges to upload a formatter can exploit this to execute arbitrary OS commands with the privileges of the GeoNetwork process.

Reference: CVE-2026-58400 on NVD

← Back to Security News