CVE-2026-46487: GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GeoNetwork’s Elasticsearch-backed search API is responsible for injecting access-control and visibility filters into every request before it reaches the underlying Elasticsearch index. Under certain request conditions, that filtering step does not run, allowing an unauthenticated user to retrieve indexed metadata records that should be restricted, including records limited to specific groups.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-46487 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →