DevSecOps Toolkit

CVE record

CVE-2026-2586

CRITICALCVSS 9.1

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

Vulnerability metadata

Published
2026-05-19T09:46:28.413Z
Modified
2026-05-21T07:48:18.210Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References