PT-2026-68489 · Eclipse · Glassfish
CVE-2026-12605
·
Published
2026-08-06
·
Updated
2026-08-06
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse GlassFish versions 8.0.x through 8.0.3
Description
A combination of Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) exists in the
DownloadServlet ContentSources. This issue allows an attacker to leak the admin gfresttoken to a host under their control if the victim is authenticated into the Admin Console. Successful exploitation can lead to a full unauthenticated takeover of the Eclipse GlassFish domain until the token expires.Recommendations
Update Eclipse GlassFish to version 8.0.4 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glassfish