PT-2026-68489 · Eclipse · Glassfish

CVE-2026-12605

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse GlassFish versions 8.0.x through 8.0.3
Description A combination of Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) exists in the DownloadServlet ContentSources. This issue allows an attacker to leak the admin gfresttoken to a host under their control if the victim is authenticated into the Admin Console. Successful exploitation can lead to a full unauthenticated takeover of the Eclipse GlassFish domain until the token expires.
Recommendations Update Eclipse GlassFish to version 8.0.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12605

Affected Products

Glassfish