216.73.217.22

CVE-2026-2586

· Published 19/05/2026 15:16 · Modified 19/05/2026 17:57

Labels: CVE-2026-2586 2026-05-19CVE-2026-2586CWE-94[email protected]

Essential information

Published
19/05/2026 15:16
Modified
19/05/2026 17:57
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
eclipse / glassfish cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*

References