CVE-2026-2586

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
References
Link Resource
https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-19 15:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-2586

Mitre link : CVE-2026-2586

CVE.ORG link : CVE-2026-2586


JSON object : View

Products Affected

eclipse

  • glassfish
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')