
European cybersecurity company Ethiack has identified four security vulnerabilities in GeoNetwork, the open source software used by governments, militaries and national agencies worldwide to operate geoportals.
Two of the vulnerabilities can be chained to form a critical pre-authentication remote code execution (Pre-Auth RCE) vulnerability. The attack could enable threat actors to gain access to networks without first obtaining or guessing user credentials. Once access is achieved, attackers could potentially take control of affected networks, exfiltrate sensitive information or deploy malware.
Originally developed by the United Nations, GeoNetwork is a geospatial metadata catalog that is now widely adopted by public sector organisations to provide geoportals. These platforms allow users to visualise, organise and filter geographical data.
Ethiack security researcher Rafael Castilho discovered the vulnerabilities and identified vulnerable systems across 121 geoportals in 39 countries.
Government, military and public sector organisations accounted for 89% of the affected geoportals, while the remaining systems were operated by academic institutions and businesses.
Ethiack chose to notify the GeoNetwork team privately rather than immediately disclose the technical details. The company subsequently worked with independent researcher Brexard, who identified the vulnerability several days later, and took a leading role in the coordinated global remediation effort. This enabled affected organisations to implement mitigations and secure their systems before an official software patch became available.
Ethiack has since published technical details of the vulnerability, along with information about its involvement in the global remediation effort, on its blog.
Jorge Monteiro, CEO at Ethiack, commented:
“Finding four vulnerabilities in a platform used so widely by governments and public bodies is significant, but the most serious issue here is the Pre-Auth RCE chain. Vulnerabilities like this can enable attackers to hack into a network quickly and easily, with no need for access credentials. Once penetrated in this way, the target organisation will be at the mercy of the attacker, who can install malware or steal data at will.
“Ethiack combines a team of world-class human hackers and AI pentesting agents, who work together 24-7 to help cyber defenders identify and validate vulnerabilities like this, along with the threat they represent.
“When dealing with a vulnerability emergency like this, we prioritise speed, agility and responsibility. We worked closely with the GeoNetwork team to support a coordinated, global remediation effort that enabled at-risk organisations to secure their assets with pre-patch mitigations while GeoNetwork developed a full patch.
“For full details of the vulnerability and how we helped more than 120 government, business and public sector organisations put things right, check out our blog post here.”
_____
About Ethiack
Ethiack is an AI-powered cybersecurity company that combines autonomous security testing technology with the creativity and skill of ethical hackers to help organisations identify and fix vulnerabilities before they can be exploited.
Its AI pentesting agents enable companies to test their entire attack surface 24/7 to reveal and validate vulnerabilities, delivering actionable results at speed and scale.
Founded in 2022 in Portugal by cybersecurity experts André Baptista and Jorge Monteiro, Ethiack is already working with leading organisations across Europe, including Portugal’s national airport operator ANA.
Ethiack is a winner of the World Summit Award, a United Nations-backed initiative recognising digital innovation with global impact, and contributes to industry cybersecurity standards through its work with international organisations and sector bodies.
Ethiack’s mission is simple: to help organisations move from reactive security to continuous, proactive defence, using ethical AI to stay ahead of accelerating, increasingly automated cyber threats.
Join our LinkedIn group Information Security Community!











