## Overview
GeoNetwork, a catalog application for managing spatially referenced resources, has a critical vulnerability identified as CVE-2026-58400. This flaw affects versions prior to 4.4.12 and 4.2.17. The Saxon XSLT processor used in GeoNetwork is misconfigured, allowing attackers to execute arbitrary commands.
## Technical Details
The vulnerability arises from the Saxon XSLT processor being set up without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). This configuration flaw means that any stylesheet uploaded to GeoNetwork can invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder`. An attacker with sufficient privileges can upload a malicious `.xsl` file that executes arbitrary operating system commands with the privileges of the GeoNetwork process user.
## Impact
Successful exploitation of this vulnerability can lead to full control over the server running GeoNetwork. An attacker could execute commands that compromise the system, steal data, or disrupt services. The CVSS score of 9.1 indicates the high severity of this issue, making it critical for organizations using GeoNetwork to act quickly.
## Mitigation
Defenders should upgrade GeoNetwork to versions 4.4.12 or 4.2.17, which contain patches addressing this vulnerability. Organizations should also review their configurations to ensure secure processing is enabled and Java extension functions are disabled. Regular audits of uploaded stylesheets and user privileges can further mitigate risks associated with this vulnerability.
CSURFACE Threat Sensor