What is CVE-2026-12605?
A CSRF + SSRF vulnerability in DownloadServlet ContentSources of Eclipse GlassFish 8.0.x prior to 8.0.4 allows leaking the admin gfresttoken to an attacker-controlled host if the victim is authenticated. This can lead to full unauthenticated takeover of the GlassFish domain until the token expires.
Azərbaycanca: Eclipse GlassFish 8.0.x versiyalarında (8.0.4-dən əvvəl) DownloadServlet ContentSources-da CSRF + SSRF zəifliyi aşkarlanıb. Autentifikasiya olunmuş admin istifadəçisi tələyə düşərsə, hücumçu admin `gfresttoken`-i ələ keçirərək domain üzərində tam nəzarəti əldə edə bilər.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
How can an attacker achieve full unauthenticated takeover of a GlassFish domain using CVE-2026-12605?
The attacker exploits the CSRF + SSRF vulnerability in DownloadServlet ContentSources by luring an authenticated admin user. If the victim is authenticated, the admin `gfresttoken` is leaked to an attacker-controlled host. This token then enables full unauthenticated takeover of the GlassFish domain until the token expires.
Which versions of Eclipse GlassFish are affected by CVE-2026-12605?
The vulnerability affects Eclipse GlassFish 8.0.x versions prior to 8.0.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.