VYPR
Critical severity9.1NVD Advisory· Published May 19, 2026· Updated Jul 24, 2026

CVE-2026-2586

CVE-2026-2586

Description

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.glassfish.main.admingui:console-commonMaven
< 8.0.28.0.2
org.glassfish.jsftemplating:jsftemplatingMaven
< 4.2.04.2.0

Affected products

4
  • Range: from 8.0.0 to 8.0.1, 7.1.0, from 7.0.0 to 7.0.25
  • Eclipse/GlassFishllm-fuzzy3 versions
    from 8.0.0 to 8.0.1, 7.1.0, from 7.0.0 to 7.0.25+ 2 more
    • (no CPE)range: from 8.0.0 to 8.0.1, 7.1.0, from 7.0.0 to 7.0.25
    • (no CPE)
    • cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*range: <8.0.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.