July security vulnerability update for fixes included in GeoNetwork 4.4.11 and 4.2.16 release:
- CVE-2026-46487 ACL bypass on Elasticsearch search when request body omits query field
- CVE-2026-53573 Open Redirect Bypass in core-geonetwork OAuth2/OIDC and Keycloak login filters
- CVE-2026-39379 Reflected XSS through client-side template injection
This is also a good opportunity to reminder our community of the coordinated vulnerability disclosure policy. This policy is setup to provide community members with an opportunity to update prior to public disclosure.
The 4.4.11 and 4.2.16 releases were published June 2nd, prior to CVE publication July 1st.