CVE-2026-2586
An authenticated attacker who can access GlassFish’s Administration Console can run arbitrary operating‑system commands with the privileges of the application service user. The flaw exists in several older GlassFish releases and has been fixed in newer versions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Eclipse GlassFish versions 5.1.0 through 6.2.5 (impact unknown), 7.0.0‑7.0.25, 7.1.0, and 8.0.0‑8.0.1. Administrators who can log into the console are at risk.
Real-world impact
An attacker could execute any command on the host machine, potentially taking full control of the server, installing malware, or exfiltrating data.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is network‑accessible, requires low effort, and allows an attacker with high privileges to gain complete control over the system, affecting confidentiality, integrity, and availability.
What to do about it
- 011. Determine the current GlassFish version you are running.
- 022. Upgrade to a fixed release: 8.0.2 or later, 7.1.1 or later, or 7.0.26 or later.
- 033. Restart the GlassFish service to apply the update.
NVD-referenced vendor advisory
Timeline
- May 19, 2026 · May 19, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- gitlab.eclipse.org/security/cve-assignment/-/i…exploitissue trackingthird party advisory