CVE-2026-2586
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 0.8%
from disclosure to weapon13 days
Published on NVDMay 19
1st PoC+13d
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Eclipse Foundation · Eclipse Glassfishpublic PoCs found — 2
githubgithub.com/DeepSecurityResearch/CVE-2026-2586★ 2githubgithub.com/GabrielHA12/Glassfish-research★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.