Cross-Site Request Forgery and Server-Side Request Forgery in Eclipse GlassFish by Eclipse Foundation
CVE-2026-12605

9.6CRITICAL

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-12605?

The Eclipse GlassFish product versions prior to 8.0.4 are vulnerable to a combination of Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to exploit the DownloadServlet ContentSources, potentially leaking the admin's gfresttoken to a malicious, attacker-controlled host. If a victim is authenticated in the Admin Console, it enables an unauthenticated takeover of the Eclipse GlassFish domain, compromising the entire server environment until the leaked token expires.

Affected Version(s)

Eclipse GlassFish 8.0.0 < 8.0.4

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://gitlab.eclipse.org/evilgensec
.