| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-96v6-hq43-x9h4 | GlassFish's Administration Console is Vulnerable to RCE |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 29 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary OS Command Execution via GlassFish Administration Console |
Mon, 29 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. |
Thu, 21 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* |
Tue, 19 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary OS Command Execution via GlassFish Administration Console | |
| First Time appeared |
Eclipse
Eclipse glassfish |
|
| Vendors & Products |
Eclipse
Eclipse glassfish |
Tue, 19 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. | |
| Weaknesses | CWE-917 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-06-29T08:34:31.867Z
Reserved: 2026-02-16T14:10:57.801Z
Link: CVE-2026-2586
Updated: 2026-05-19T14:40:53.226Z
Status : Analyzed
Published: 2026-05-19T15:16:28.413
Modified: 2026-06-17T10:31:21.593
Link: CVE-2026-2586
No data.
OpenCVE Enrichment
Updated: 2026-06-29T10:00:11Z
Github GHSA