Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Glassfish-research — CVE-2026-2586 — Eclipse GlassFish EL injection to RCE | Kitploit
Tools/GitHubGitHub/gabrielha12/glassfish-research
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubgabrielha12/glassfish-research

Glassfish-research

CVE-2026-2586 — Eclipse GlassFish EL injection to RCE

View Repository
21 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GlassFish Security Research

Vulnerability research on the Eclipse GlassFish administration console.

CVEIssueSeverityStatus
CVE-2026-2586EL injection → RCE9.1 CriticalFixed in 8.0.2
———Pending disclosure

CVE-2026-2586 — EL Injection to RCE

Affected: < 8.0.2 · CWE-917 · Authenticated RCE

The alertSummary and alertDetail parameters exist to render a status message after saving a configuration. Their values were passed back through the server-side Expression Language engine before rendering, letting an authenticated console user reach Java classes through Reflection and execute OS commands as the GlassFish process.

Download Tool