Critical severity9.1NVD Advisory· Published May 19, 2026· Updated May 21, 2026
CVE-2026-2586
CVE-2026-2586
Description
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish.main.admingui:console-commonMaven | < 8.0.2 | 8.0.2 |
org.glassfish.jsftemplating:jsftemplatingMaven | < 4.2.0 | 4.2.0 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-96v6-hq43-x9h4ghsaADVISORY
- gitlab.eclipse.org/security/cve-assignment/-/issues/87nvdIssue TrackingThird Party AdvisoryExploitWEB
- nvd.nist.gov/vuln/detail/CVE-2026-2586ghsaADVISORY
- github.com/eclipse-ee4j/glassfish/releases/tag/8.0.2ghsaWEB
News mentions
0No linked articles in our index yet.