PT-2026-46854 · Maven · Org.Glassfish.Jsftemplating:Jsftemplating+1
Published
2026-05-19
·
Updated
2026-05-19
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Org.Glassfish.Jsftemplating:Jsftemplating
Org.Glassfish.Main.Admingui:Console-Common