---
id: CVE-2026-2586
title: >-
  An authenticated Remote Code Execution (RCE) vulnerability was identified in
  GlassFish's Administration Console
summary: >-
  An authenticated Remote Code Execution (RCE) vulnerability was identified in
  GlassFish's Administration Console. A user with access to the panel can send
  crafted requests that allow the execution of arbitrary operating system
  commands wi…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-917
published: '2026-05-19'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2586'
references:
  - url: 'https://gitlab.eclipse.org/security/cve-assignment/-/issues/87'
    label: emo@eclipse.org
tags:
  - nvd
  - exploit-available
epss: 0.00842
epssPercentile: 0.56428
ingestedAt: '2026-06-29T13:42:11.955Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/DeepSecurityResearch/CVE-2026-2586'
    - 'https://github.com/GabrielHA12/Glassfish-research'
  checkedAt: '2026-09-24T07:53:01.259Z'
exploitAvailable: true
---

## Overview

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
