Eclipse GlassFish disclosed CVE-2026-12605, a critical CVSS 9.6 vulnerability affecting 8.0.x releases before 8.0.4. The flaw chains CSRF and SSRF in the Admin Console's DownloadServlet and its ContentSources, allowing an attacker to induce a logged-in administrator to visit a crafted URL and trigger a server-side request to an attacker-controlled host. During that request, the server can leak the live admin gfresttoken, exposing credentials intended for GlassFish management operations.
With the stolen token, an attacker can access /management/* endpoints and take over the GlassFish domain without further authentication until the token expires. Eclipse reports the issue was reproduced on 8.0.2 and 8.0.3-SNAPSHOT, confirmed by maintainers, and fixed in GlassFish 8.0.4, with backports planned for 7.1 and 7.0. The vulnerability is tracked under CWE-918 and can lead to deployment of a malicious WAR file and remote code execution as the GlassFish process user.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The reserved CVE entry for the Eclipse GlassFish vulnerability was published, changing the issue status from reserved to published. The published record describes token leakage via DownloadServlet ContentSources and notes that GlassFish 8.0.4 is not affected.
The Eclipse Foundation, acting as CNA, reserved CVE-2026-12605 for the critical GlassFish CSRF and SSRF vulnerability tracked from report #445. The reservation record ties the CVE to affected versions 8.0.0 through before 8.0.4.
The Eclipse Foundation opened vulnerability report #445 for the GlassFish issue, documenting the DownloadServlet ContentSources flaw and its impact. The report credits the researcher and records the issue as confirmed by project maintainers.
Sujal Tuladhar discovered a critical CSRF-plus-SSRF vulnerability in Eclipse GlassFish that could leak an administrator's gfresttoken and enable unauthenticated takeover of the domain. The report states the issue was reproducible on GlassFish 8.0.2 and master/8.0.3-SNAPSHOT.
Project maintainers confirmed the issue was fixed in GlassFish 8.0.4, the first version not listed as affected. They also stated that backports to the 7.1 and 7.0 branches were planned.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecve.org
Open sourcegitlab.eclipse.org
Open sourcegitlab.eclipse.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.