CVE 9.6 CRITICAL

CVE-2026-2587_CVE-2026-2587

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) โ€œexpressionsโ€ are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement.

AI Analysis

Remote Code Execution (RCE) vulnerability in Eclipse Glassfish due to unsanitized Expression Language (EL) expressions

Basic Information

ID CVE-2026-2587
Source eclipse
Published May 19, 2026 at 14:03

Affected Product

Vendor Eclipse Foundation
Product Eclipse Glassfish
Affected Versions Eclipse Foundation Eclipse Glassfish 0
Eclipse Foundation Eclipse Glassfish 8.0.0

CWE Classification

AI Assessment

AI Score 9.6 / 10
AI Severity Critical
Vendor Eclipse Foundation
Product Eclipse Glassfish
Version 0, 8.0.0

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.