CVE-2026-2586

Source
https://cve.org/CVERecord?id=CVE-2026-2586
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2586.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2586
Aliases
Published
2026-05-19T14:12:06.459Z
Modified
2026-07-27T03:56:30.733589108Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2586.json",
    "cwe_ids": [
        "CWE-917",
        "CWE-94"
    ],
    "cna_assigner": "eclipse"
}
References

Affected packages

Git / github.com/eclipse-ee4j/glassfish

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-ee4j/glassfish
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.26"
        },
        {
            "introduced": "7.1.0"
        },
        {
            "fixed": "7.1.1"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2586.json"