CVE-2026-12605: Eclipse Glassfish
Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
Affected products
- Eclipse Glassfish: from 8.0.0, before 8.0.4 (fixed in 8.0.4)
Published 2026-08-06. Last modified 2026-08-10.