CVSS
9.6
CVSS v3.1
EPSS
0.2%
Exploit Prediction Score
Published
August 6, 2026
Exploitability
EPSS probability 0.2%
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).