Junglewise Threat Intelligence

CVE-2026-2586: Eclipse GlassFish RCE via EL Injection in Administration Console

CVE-2026-2586 · Severity: critical · CVSS 9.1 · Published 2026-05-19

Technologies: org.glassfish.main.admingui:console-common (Maven), Eclipse Foundation GlassFish. Vendors: Eclipse Foundation, Maven.

Executive brief

Eclipse GlassFish is an application server used to deploy and manage enterprise Java applications. A security vulnerability in its web-based administration console allows an authorized administrator to execute malicious commands on the underlying server. This could lead to a complete takeover of the server, unauthorized access to sensitive data, or disruption of hosted services.

Technical details

An authenticated Remote Code Execution (RCE) vulnerability exists in the GlassFish Administration Console due to an Expression Language (EL) injection flaw (CWE-917/CWE-94). The vulnerability is rooted in the 'jsftemplating' component and the 'console-common' module, where externally-influenced input is incorrectly neutralized before being processed as code. An attacker with high privileges (administrative access to the console) can send crafted network requests to execute arbitrary OS commands with the permissions of the GlassFish service user. The issue is resolved in GlassFish version 8.0.2 and jsftemplating version 4.2.0.

Affected products

  • Eclipse Foundation GlassFish < 8.0.2
  • GlassFish jsftemplating < 4.2.0

Timeline

  • 2025-12-09: disclosed: Vulnerability reported to Eclipse Foundation
  • 2026-05-05: patched: GlassFish 8.0.2 released with fixes
  • 2026-05-19: advisory: GitHub Advisory and NVD entry published

References

Related threats