SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-2586

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console.

CRITICAL 9.1EPSS 0.84%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.84% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-94, CWE-917
Affected
eclipse/glassfish
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.