Executive brief
GeoNetwork is an open-source catalog application used to manage and publish spatially referenced resources. A security flaw in its search functionality allows unauthorized users to bypass access controls and view private metadata records. This could lead to the exposure of sensitive internal data, draft records, or information restricted to specific organizational groups.
Technical details
An authorization bypass (CWE-862) exists in GeoNetwork 4.x's search proxy layer. The application is designed to inject access-control and visibility filters into client-supplied Elasticsearch requests to enforce group-based visibility and ownership checks. However, if a search request body omits the 'query' field, the filter-injection step is skipped, and the request is forwarded to the underlying Elasticsearch index without restrictions. An unauthenticated attacker can exploit this via the network to retrieve the full contents of restricted metadata records. The issue is patched in versions 4.2.16 and 4.4.11.
Affected products
- GeoNetwork GeoNetwork >= 4.0.0-alpha.1, <= 4.0.6-0; >= 4.2.0, <= 4.2.15; >= 4.4.0, <= 4.4.10-0
Timeline
- 2026-07-01: advisory: GitHub Advisory GHSA-582q-v28r-7cxr published
- 2026-07-01: disclosed: CVE-2026-46487 disclosed