CVE-2026-2586

CRITICAL

Eclipse Glassfish - Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Title source: rule
STIX 2.1

Description

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

Scores

CVSS v3 9.1
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-917 CWE-94
Status published
Products (4)
eclipse/glassfish < 8.0.2
Eclipse Foundation/Eclipse Glassfish 7.1.0
Eclipse Foundation/Eclipse Glassfish 8.0.0
Eclipse Foundation/Eclipse Glassfish 8.0.2
Published May 19, 2026
Tracked Since May 19, 2026