PT-2026-66870 · Unknown · Geonetwork

CVE-2026-53573

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GeoNetwork versions 3.12.0 through 4.2.15 GeoNetwork versions 4.4.0 through 4.4.10
Description Unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter allows an attacker to redirect users to an external site after login. Although the application attempts to restrict redirect targets to relative, in-application URLs, the validation fails to reject all URL types that cause the browser to leave the origin. An attacker can craft a link to a legitimate OAuth2/OIDC or Keycloak login endpoint that forwards the victim to an arbitrary external host upon completion of the login flow, which can be used for phishing attacks.
Recommendations Update to version 4.2.16 or later. Update to version 4.4.11 or later.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53573
GHSA-PJP7-Q6WP-97QX

Affected Products

Geonetwork