Vendor
Unauthenticated Server-Side Request Forgery in GeoNetwork Web Module
1 rule 2 TTPsAn unauthenticated server-side request forgery vulnerability (CVE-2026-55864) in the GeoNetwork SLD tool allows attackers to perform unauthorized outbound requests and potentially disclose internal XML data.
GeoNetwork Reflected XSS through Client-Side Template Injection (CVE-2026-39379)
1 rule 4 TTPsA reflected Cross-Site Scripting (XSS) vulnerability, CVE-2026-39379, exists in GeoNetwork due to client-side template injection within error pages, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript to execute in their browser in the context of their authenticated session.
GeoNetwork ACL Bypass in Elasticsearch Search (CVE-2026-46487)
3 TTPsA high-severity authorization bypass vulnerability, CVE-2026-46487, in GeoNetwork's Elasticsearch-backed search API allows unauthenticated attackers to retrieve restricted metadata records by bypassing access control and visibility filters when the request body omits the 'query' field, leading to sensitive information disclosure.