In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127 | Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445 | Exploit Vendor Advisory |
Configurations
History
10 Aug 2026, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Eclipse
Eclipse glassfish |
|
| CPE | cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* | |
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127 - Vendor Advisory | |
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445 - Exploit, Vendor Advisory |
06 Aug 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-06 14:16
Updated : 2026-08-10 14:54
NVD link : CVE-2026-12605
Mitre link : CVE-2026-12605
CVE.ORG link : CVE-2026-12605
JSON object : View
Products Affected
eclipse
- glassfish
CWE
CWE-918
Server-Side Request Forgery (SSRF)
