An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
29 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. |
17 Jun 2026, 10:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 - Exploit, Issue Tracking, Third Party Advisory |
21 May 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Eclipse
Eclipse glassfish |
|
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 - Issue Tracking, Third Party Advisory, Exploit | |
| CPE | cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* |
19 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 15:16
Updated : 2026-06-29 09:16
NVD link : CVE-2026-2586
Mitre link : CVE-2026-2586
CVE.ORG link : CVE-2026-2586
JSON object : View
Products Affected
eclipse
- glassfish
