CVE-2026-2586: Code Injection
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
eclipse/glassfishto a version that resolves this vulnerability.Fixed in 8.0.2 - Upgrade
Upgrade
eclipse/glassfishto a version that resolves this vulnerability.Fixed in 7.1.1 - Upgrade
Upgrade
eclipse/glassfishto a version that resolves this vulnerability.Fixed in 7.0.26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2586?
CVE-2026-2586 is classified as a high-severity vulnerability due to its potential for remote code execution.
How can I mitigate CVE-2026-2586?
To mitigate CVE-2026-2586, ensure that access to the GlassFish Administration Console is restricted to trusted users only.
What types of exploits are possible with CVE-2026-2586?
Exploiting CVE-2026-2586 allows unauthenticated users to execute arbitrary OS commands on the server running GlassFish.
Which version of Oracle GlassFish is affected by CVE-2026-2586?
CVE-2026-2586 affects the Oracle GlassFish Administration Console without specific version limitations listed.
Who is impacted by CVE-2026-2586?
Any organization using Oracle GlassFish Administration Console with insufficient access controls is potentially impacted by CVE-2026-2586.