CVE-2026-2587Disclosure(eclipse / glassfish)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch eclipse glassfish systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-917

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glassfish

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
glassfish

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-20: 1Mentions · 2026-05-30: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-30: 105-1905-2005-30
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-192
Disclosure2
2026-05-201
General1
2026-05-301
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-2587 (CVSS 9.6) - RCE in Glassfish gadget handler via unsanitized Expression Language processing in .xml files. Remote attackers can achieve full host compromise. Patch immediately. #CVE #PatchNow https://t.co/K765oc5DuM

    Post summary

    The tweet announces a critical RCE in Glassfish (CVE‑2026‑2587) and urges immediate patching, but does not provide PoC code or evidence of active exploitation.

    0001063
    32 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Eclipse GlassFish EL Injection RCE (CVE-2026-2587) A critical Expression Language (EL) injection vulnerability in Eclipse GlassFish may allow remote attackers to achieve full remote code execution through crafted .xml files processed by the GlassFish gadget handler. The issue affects GlassFish 8.0.0 and versions prior to 7.1.0 on both Windows and Linux. Successful exploitation may lead to arbitrary command execution, persistence, data compromise, and lateral movement. 👉 Administrators should restrict processing of untrusted XML input and monitor Eclipse security advisories for remediation guidance.

    Post summary

    The post announces CVE-2026-2587, an EL injection leading to RCE in Eclipse GlassFish, and advises admins to restrict XML processing and consult advisories for remediation.

    0001075
    196 followersView on X
  • Camilo G. AkA Dedalo@seguridadblanca
    General

    #cve-2026-2587 https://t.co/7DetEsQHC3

    Post summary

    This tweet only references CVE-2026-2587 and includes a link, but no further information is provided.

    0000053
    22 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2587 A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The applicatio… https://www.cve.org/CVERecord?id=CVE-2026-2587

    Post summary

    The text announces a critical RCE vulnerability (CVE‑2026‑2587) in Glassfish’s gadget handler, providing basic technical details but no exploit, patch, or exploitation evidence.

    00000146
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipseglassfish---

Explore more