CVE-2026-12605: Eclipse Glassfish

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

Affected products

  • Eclipse Glassfish: from 8.0.0, before 8.0.4 (fixed in 8.0.4)

Published 2026-08-06. Last modified 2026-08-10.