CVE-2026-2586 is an authenticated remote code execution vulnerability in the Eclipse GlassFish Administration Console caused by unsafe evaluation of attacker-controlled Expression Language input. The flaw affects the administration console’s server-side templating and request handling, where parameters such as alertSummary and alertDetail supplied to console endpoints can be evaluated without sufficient sanitization or restriction. By injecting crafted EL expressions, an authenticated administrator can reach dangerous Java functionality, including invocation paths to java.lang.Runtime, and execute arbitrary operating system commands on the underlying host. The commands run with the privileges of the GlassFish service account. Confirmed affected versions include Eclipse GlassFish 7.1.0 and 8.0.0, with broader vendor guidance indicating fixes in 8.0.2, 7.1.1, and 7.0.26 for affected release lines.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC for CVE-2026-2586 affecting the Eclipse GlassFish administration console. It contains two files: a Python exploit script and a README describing the vulnerability. The Python script is the sole code file and clear entry point. It uses the requests library to authenticate to the GlassFish admin console at /common/j_security_check with supplied credentials, then issues a crafted request to /web/configuration/virtualServerEdit.jsf. The exploit abuses the alertSummary parameter to inject a Java Expression Language payload that reaches java.lang.Runtime via reflection and executes an OS command. The command is embedded as base64, decoded on the target, and piped into bash for execution. The script is operational rather than a mere detector: it supports three reverse shell payload variants (bash, netcat/FIFO, python3), accepts attacker-controlled callback host and port, and can disable TLS verification. The exploit is authenticated RCE and depends on valid credentials plus a vulnerable GlassFish version reportedly fixed in 8.0.2. Overall, the repository’s purpose is to demonstrate and validate authenticated EL-injection-to-RCE leading to a reverse shell on vulnerable GlassFish admin interfaces.
This repository is a small, single-purpose authenticated RCE exploit for CVE-2026-2586 affecting the GlassFish/Payara Administration Console. It contains one Python exploit script and a README describing the vulnerability and usage. The script uses the requests library to establish an authenticated session against the admin login endpoint /common/j_security_check, then sends a GET request to the virtual server configuration page /web/configuration/virtualServerEdit.jsf with a malicious alertSummary parameter containing a URL-encoded EL expression. That expression invokes java.lang.Runtime.getRuntime().exec() on the server. The exploit’s main capability is remote command execution after successful authentication. Its intended post-exploitation outcome is a reverse shell. It supports three hardcoded shell payload variants: a bash /dev/tcp shell, a netcat+FIFO shell using /tmp/f, and a python3 socket-based shell. The selected command is base64-encoded and inserted into the EL payload before delivery. The script accepts operator-controlled parameters for target URL, username, password, callback host, callback port, shell type, TLS verification bypass, and verbosity. Repository structure is minimal: CVE-2026-2586.py is the executable entry point and README.md provides context and an example invocation. This is not a framework module and not a detection script. It is a real exploit PoC with operational payload delivery, but payload customization is limited to a few predefined reverse shell templates.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate GlassFish authenticated admin RCE vulnerability referenced for comparison with the newly reported unauthenticated token-theft-to-RCE issue.
An authenticated remote code execution vulnerability in GlassFish Administration Console that allows a user with panel access to send crafted requests and execute arbitrary OS commands as the application service user.
An Expression Language injection vulnerability in the Eclipse GlassFish Administration Console that allows an authenticated administrator to execute arbitrary OS commands on the underlying host.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.