AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-12605

CRITICAL · CVSS 9.6 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Eclipse GlassFish versions prior to 8.0.4 are vulnerable to a critical CSRF and SSRF attack in the DownloadServlet, which allows an attacker to leak the admin `gfresttoken` to a malicious host if the victim is authenticated in the Admin Console. This vulnerability enables an unauthenticated attacker to take over the Eclipse GlassFish domain until the token expires. Organizations using affected versions should prioritize immediate updates to mitigate this severe risk.

CVE
CVE-2026-12605
Severity
CRITICAL
CVSS
9.6
EPSS
0.24%

Original NVD Description

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

Related CVEs

Other vulnerabilities affecting the same vendor(s)