๐Ÿ” CVE Alert

CVE-2026-12605

CRITICAL 9.6
CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

CWE CWE-918
Vendor eclipse foundation
Product eclipse glassfish
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse glassfish

Be the first to know when new critical vulnerabilities affecting eclipse foundation eclipse glassfish are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Eclipse Foundation / Eclipse GlassFish
8.0.0 < 8.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127

Credits

https://gitlab.eclipse.org/evilgensec