
Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server configuration flow.
An Expression Language Injection vulnerability in the GlassFish Administration Console allows an authenticated user to inject malicious EL expressions into parameters processed by the administrative web interface. Successful exploitation may lead to remote command execution on the affected server.
The vulnerability was identified in the server virtual configuration editing flow, where user-controllable parameters are interpreted insecurely by the application.
This occurs because:
The test was performed in a local and controlled environment.
CVE-2026-2586.py --url https://glassfish:4848/ --user <USERNAME> --password <PASSWORD> --lhost 127.0.0.1 --lport 4444 --insecure
Vulnerable URL:
AUTHORIZED USE ONLY. DeepSecurity Perú does not endorse unauthorized access and takes no responsibility for any misuse of the information provided.