Critical severity9.1NVD Advisory· Published May 19, 2026· Updated Jul 24, 2026
CVE-2026-2586
CVE-2026-2586
Description
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish.main.admingui:console-commonMaven | < 8.0.2 | 8.0.2 |
org.glassfish.jsftemplating:jsftemplatingMaven | < 4.2.0 | 4.2.0 |
Affected products
4- Range: from 8.0.0 to 8.0.1, 7.1.0, from 7.0.0 to 7.0.25
Patches
Vulnerability mechanics
References
4- gitlab.eclipse.org/security/cve-assignment/-/issues/87nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-96v6-hq43-x9h4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-2586ghsaADVISORY
- github.com/eclipse-ee4j/glassfish/releases/tag/8.0.2ghsaWEB
News mentions
0No linked articles in our index yet.