PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12605 Eclipse Foundation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:20.887Z and has not been modified since then. The vulnerability affects Eclipse GlassFish versions 8.0.x before 8.0.4. A CSRF and SSRF vulnerability in DownloadServlet ContentSources leaks the admin `gfresttoken` to an attacker-controlled host if the victim is authenticated into the Admin Console, potentially allowing full unauthenticated takeover of the Eclipse GlassFish domain until the token expires. Defenders should verify affected scope, review official advisories, and monitor for suspicious activity. The source-confidence limits and review context should also be considered when assessing the vulnerability and implementing mitigations.

Vendor
Eclipse Foundation
Product
Eclipse GlassFish
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Administrators and users of Eclipse GlassFish versions 8.0.x before 8.0.4, security teams monitoring for potential token leaks and domain takeovers, and operators responsible for patching and securing the affected systems should prioritize patching and review compensating controls to prevent potential full unauthenticated takeover of the Eclipse GlassFish domain. Additionally, platform and vulnerability-management teams should review the vulnerability and implement necessary mitigations to prevent exploitation. Security teams should also monitor for suspicious activity and token usage to detect potential attacks. Asset inventory and configuration management teams may need to verify affected product deployments and assign owners for follow-up. Change management and incident response teams should plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compliance and risk management teams may need to review and update risk assessments and mitigation strategies. IT and development teams may need to implement compensating controls for exposed systems while remediation is scheduled and verified. Audit and assurance teams may need to review and verify the implementation of mitigations and compensating controls. Business continuity and disaster recovery teams may need to review and update plans to ensure continuity in the event of an exploitation. Communication and stakeholder management teams should be informed of the vulnerability and the necessary actions to take. The affected product deployments should be reviewed to determine the operational impact of the vulnerability and the necessary steps to mitigate it. The vulnerability class and the affected product context should be reviewed to determine the potential impact on the organization. The source-confidence limits and review context should also be considered when assessing the vulnerability and implementing mitigations. The defensive impact of the vulnerability and the necessary steps to prevent exploitation should be reviewed and implemented. The affected operator and platform impact should be assessed and mitigations implemented to prevent exploitation. The who

Technical summary

A CSRF and SSRF vulnerability in DownloadServlet ContentSources of Eclipse GlassFish versions 8.0.x before 8.0.4 leaks the admin `gfresttoken` to an attacker-controlled host if the victim is authenticated into the Admin Console, potentially allowing full unauthenticated takeover of the Eclipse GlassFish domain until the token expires. This vulnerability affects administrators and users of the affected versions.

Defensive priority

Organizations using Eclipse GlassFish versions 8.0.x before 8.0.4 should prioritize patching to prevent potential full unauthenticated takeover of the Eclipse GlassFish domain.

Recommended defensive actions

  • Inventory and verify Eclipse GlassFish version
  • Apply patches or upgrades to version 8.0.4 or later
  • Monitor for suspicious activity and token usage
  • Restrict access to the Admin Console
  • Implement compensating controls for token security

Evidence notes

Evidence is limited; primary official records indicate a CSRF and SSRF vulnerability in DownloadServlet ContentSources of Eclipse GlassFish versions 8.0.x before 8.0.4, which leaks the admin `gfresttoken` to an attacker-controlled host if the victim is authenticated into the Admin Console. Defenders should verify affected scope, review official advisories, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:20.887Z and has not been modified since then.