CVE-2026-58400 | GeoNetwork up to 4.2.16/4.4.11 XSLT Processor java.lang.Runtime.exec os command injection

SecurityVulns

A vulnerability has been found in GeoNetwork up to 4.2.16/4.4.11 and classified as problematic. This affects the function java.lang.Runtime.exec of the component XSLT Processor. This manipulation causes os command injection.

This vulnerability is tracked as CVE-2026-58400. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More