Sceawere

Vulnerability Detail

CVE-2026-12605UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Eclipse GlassFish CSRF and SSRF Admin Token Leak

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
1d ago
Vendor
Eclipse Foundation
Product
Eclipse GlassFish
Attack Type
CWE-918
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-08-06T14:16:20.887Z",
  "pubdate": "2026-08-06T14:16:20.887Z",
  "executiveSummary": "A critical security vulnerability involving Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) exists within the DownloadServlet ContentSources component of Eclipse GlassFish versions 8.0.x prior to 8.0.4. This vulnerability enables an attacker to leak the administrative gfresttoken to an external attacker-controlled host, provided that an authenticated administrative victim interacts with a malicious payload while logged into the Admin Console. Successful exploitation achieves a full unauthenticated takeover of the Eclipse GlassFish domain, which persists until the administrative token expires. The risk implication is severe, allowing complete administrative compromise of the affected application server through a combination of browser-based coercion and server-side request redirection.",
  "technicalDetails": "The vulnerability stems from insufficient validation and request handling within the DownloadServlet ContentSources component of Eclipse GlassFish. The root cause is a compound flaw integrating a Cross-Site Request Forgery vector that tricks an authenticated administrator into executing unauthorized requests against the Admin Console, combined with a Server-Side Request Forgery condition that causes the server to initiate arbitrary outbound connections.\nThe attack flow proceeds as follows: First, an attacker crafts a malicious webpage or payload designed to trigger a Cross-Site Request Forgery attack against the vulnerable Eclipse GlassFish Admin Console. Second, the victim, who must be currently authenticated into the Admin Console, accesses the malicious content, causing their browser to issue an unintended request to the DownloadServlet ContentSources endpoint. Third, upon receiving this coerced request, the vulnerable servlet leverages its Server-Side Request Forgery capabilities to initiate an outbound connection to an attacker-controlled host.\nDuring this outbound request triggered by the SSRF condition, the server inadvertently leaks the administrative gfresttoken parameter to the remote endpoint controlled by the attacker. Once the attacker captures the valid gfresttoken, they bypass authentication entirely and gain full unauthenticated administrative control over the Eclipse GlassFish domain. This unauthorized access remains valid and functional until the compromised token naturally expires.\nThe affected product is Eclipse GlassFish versions 8.0.x before 8.0.4. The vulnerable component is the DownloadServlet ContentSources. Exploitation requires the target to be authenticated into the Admin Console and tricked into interacting with the malicious request vector, operating across network exposures accessible to web-based attackers."
}
CVE-2026-12605: Eclipse GlassFish CSRF and SSRF Admin Token Leak (CRITICAL Severity, CVSS: 9.6) - Sceawere