GHSA-96v6-hq43-x9h4CriticalCVSS 9.1

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's...

Published
May 19, 2026
Last Modified
May 19, 2026

🔗 CVE IDs covered (1)

📋 Description

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

🔗 References (3)