CVE-2026-2586

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.
References
Link Resource
https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 Issue Tracking Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*

History

21 May 2026, 13:18

Type Values Removed Values Added
First Time Eclipse
Eclipse glassfish
References () https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 - () https://gitlab.eclipse.org/security/cve-assignment/-/issues/87 - Issue Tracking, Third Party Advisory, Exploit
CPE cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*

19 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 15:16

Updated : 2026-05-21 13:18


NVD link : CVE-2026-2586

Mitre link : CVE-2026-2586

CVE.ORG link : CVE-2026-2586


JSON object : View

Products Affected

eclipse

  • glassfish
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')