Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-96v6-hq43-x9h4 | GlassFish's Administration Console is Vulnerable to RCE |
Mon, 29 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary OS Command Execution via GlassFish Administration Console |
Mon, 29 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. |
Thu, 21 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:* |
Tue, 19 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary OS Command Execution via GlassFish Administration Console | |
| First Time appeared |
Eclipse
Eclipse glassfish |
|
| Vendors & Products |
Eclipse
Eclipse glassfish |
Tue, 19 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. | |
| Weaknesses | CWE-917 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-06-29T08:34:31.867Z
Reserved: 2026-02-16T14:10:57.801Z
Link: CVE-2026-2586
Updated: 2026-05-19T14:40:53.226Z
Status : Analyzed
Published: 2026-05-19T15:16:28.413
Modified: 2026-06-17T10:31:21.593
Link: CVE-2026-2586
No data.
OpenCVE Enrichment
Updated: 2026-06-29T10:00:11Z
Github GHSA