← Vulnerability feed

Vulnerability record · CVE-2026-2587 · published 19 May 2026

CVE-2026-2587: Eclipse glassfish expression language injection vulnerability

Eclipse · Glassfish

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

9.6 CVSS 3.1 Critical EPSS 0.67% · top 50.1% CWE-917 · Expression language injection
9.6CVSS 3.1 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
24 Jul 2026Last modified by NVD

Description

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.eclipse.org/security/cve-assignment/-/issues/86 ExploitIssue TrackingThird Party Advisory

Track CVE-2026-2587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5763Eclipse glassfish improper input validation vulnerabilityIn Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious c…EPSS 0.65%9.6CVE-2026-12605Eclipse glassfish server-side request forgery (ssrf) vulnerabilityIn Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …EPSS 0.43%9.1CVE-2026-2586Eclipse glassfish code injection vulnerabilityAn authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can …EPSS 0.83%8.9CVE-2024-9408Eclipse glassfish server-side request forgery (ssrf) vulnerabilityIn Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.EPSS 0.29%7.5CVE-2022-2712Eclipse glassfish path traversal vulnerabilityIn Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting wi…EPSS 0.94%6.9CVE-2024-9329Eclipse glassfish open redirect vulnerabilityIn Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the reque…EPSS 0.72%6.3CVE-2024-9342Eclipse glassfish improper restriction of authentication attempts vulnerabilityIn Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed logi…EPSS 0.41%6.1CVE-2024-10032Eclipse glassfish cross-site scripting vulnerabilityIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2026-2587), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.