CVE-2026-2586
Critical · CVSS 9.1Eclipse GlassFish Administration Console — Authenticated Remote Code Execution via Expression Language Injection (CWE-94, CWE-917)
- CVSS
- 9.1
- nvd
- EPSS
- 0.84%
- 54th pct
- KEV
- No
- Class
- oss containerizable
- CWE-94, CWE-917
Description
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
Search profile — drives PoC discovery
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 2
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Maven | org.glassfish.jsftemplating:jsftemplating | 0 → 4.2.0 |
| Maven | org.glassfish.main.admingui:console-common | 0 → 8.0.2 |
References
Status: enriched · ingested 2026-06-29T12:00:49.000Z · profiled 2026-07-01T00:30:14.000Z