Seinwacht
Terug naar meldingen
hoogENISA EU Vulnerability DatabaseAdvisory

CVE-2026-63219: core-geonetwork, actief misbruikt

Actief misbruik
Ja, bevestigd
Hoogste CVSS
8,6 hoog
Kans op misbruik (EPSS)
0,5%
Prioriteit
48 van 100

Uit de melding

GeoNetwork is a catalog application to manage spatially referenced resources.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage.17.

Lees de volledige melding bij ENISA EU Vulnerability DatabaseBron: ENISA EU Vulnerability Database, ENISA, hergebruik met bronvermelding.

CVE-2026-63219: core-geonetwork, actief misbruikt | Seinwacht