PT-2026-46854 · Maven · Org.Glassfish.Jsftemplating:Jsftemplating+1

Published

2026-05-19

·

Updated

2026-05-19

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-96V6-HQ43-X9H4

Affected Products

Org.Glassfish.Jsftemplating:Jsftemplating
Org.Glassfish.Main.Admingui:Console-Common