Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Eclipse Foundation Eclipse GlassFish — In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C H H H 9.6 .0024 14.9 —
AFFECTED
Product Versions Fixed
Eclipse GlassFish 8.0.0 – —
TIMELINE
Jun 18 Reserved by eclipse
Aug 6 EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added.
Aug 6 Published (CNA: eclipse)
Description
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 18, 2026 | Reserved | Reserved by eclipse |
| August 6, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added. |
| August 6, 2026 | Published | Published (CNA: eclipse) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Eclipse Foundation | Eclipse GlassFish | — | 8.0.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-12605 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.