Cross-Site Request Forgery and Server-Side Request Forgery in Eclipse GlassFish by Eclipse Foundation
CVE-2026-12605
9.6CRITICAL
What is CVE-2026-12605?
The Eclipse GlassFish product versions prior to 8.0.4 are vulnerable to a combination of Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to exploit the DownloadServlet ContentSources, potentially leaking the admin's gfresttoken to a malicious, attacker-controlled host. If a victim is authenticated in the Admin Console, it enables an unauthenticated takeover of the Eclipse GlassFish domain, compromising the entire server environment until the leaked token expires.
Affected Version(s)
Eclipse GlassFish 8.0.0 < 8.0.4
