CVE-2026-2587
Eclipse Foundation Eclipse Glassfish, glassfish 취약점
- 대응 우선순위
- 점검
- CVSS
- 9.6
- EPSS
- 0.63% 백분위 45.5% · 2026.06.29 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.20
CVSS 위험도가 높아 영향 여부를 우선 점검할 취약점
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary comman...
공급사 Eclipse Foundation
제품 Eclipse Glassfish, glassfish
영향 버전 7.0.0, 7.1.0, 8.0.0, < 8.0.2
수정 버전 8.0.2
CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE CWE-917
EPSS 데이터 기준일 2026.06.29