CVE-2026-2587
Java 취약성 분석 및 완화

개요

CVE-2026-2587 is a critical Remote Code Execution (RCE) vulnerability in the server-side template rendering mechanism of Eclipse GlassFish's gadget handler, classified as an Expression Language (EL) Injection (CWE-917). The vulnerability affects org.glassfish.jsftemplating:jsftemplating versions before 4.2.0 and org.glassfish.main.admingui:admingui versions before 8.0.2 (Eclipse GlassFish before 8.0.2). It was published on May 19, 2026, with a patch released the same day. The CVSS v3.1 base score is 9.6 (Critical) (GitHub Advisory, Eclipse CVE Assignment).

기술적 세부 사항

The root cause is improper neutralization of special elements in Expression Language statements (CWE-917) within GlassFish's gadget handler. The application processes .xml files and evaluates user-supplied values in a context where EL expressions (e.g., #{7*7}) are resolved server-side without sanitization or escaping. An attacker can inject malicious EL expressions into XML gadget parameters, which are then evaluated by the server, confirming RCE when the server returns the computed result (e.g., 49). A public PoC exploit script (CVE-2026-2587-Exploit-POC.py) is available that authenticates to the admin console, hosts a malicious XML probe with an EL canary, triggers the gadget.jsf endpoint, and confirms RCE (GitHub Advisory, PoC GitHub).

영향

Successful exploitation allows a remote attacker to fully compromise the underlying host running GlassFish. Consequences include arbitrary command execution, reading and modifying sensitive data, establishing persistence on the compromised system, and lateral movement within the broader infrastructure. All three security pillars — confidentiality, integrity, and availability — are rated High, and the changed scope indicates impact can extend beyond the vulnerable component itself (GitHub Advisory, Eclipse CVE Assignment).

착취 단계

  1. Reconnaissance: Identify internet-facing GlassFish instances (versions before 8.0.2) using tools like Shodan or Censys, targeting exposed admin console ports (default: 4848) or the gadget.jsf endpoint.
  2. Authentication: Authenticate to the GlassFish admin console using valid credentials (the PoC supports --username and --password parameters; default or weak credentials may be targeted).
  3. Host malicious XML probe: Set up a local HTTP server (built into the PoC script via --listen) to serve a crafted .xml file containing an EL canary expression such as #{7*7}.
  4. Trigger gadget handler: Send a request to the gadget.jsf endpoint with a parameter pointing to the attacker-controlled XML file URL (--callback-url), causing the server to fetch and process the malicious XML.
  5. Confirm EL evaluation: Verify that the server evaluates the EL expression server-side (e.g., returns 49 for #{7*7}), confirming RCE capability.
  6. Execute arbitrary commands: Replace the canary EL expression with a malicious payload (e.g., #{Runtime.getRuntime().exec('...')}) to execute arbitrary OS commands, establish a reverse shell, exfiltrate data, or deploy persistence mechanisms (PoC GitHub, GitHub Advisory).

타협의 징후

  • Network: Unusual HTTP requests to the gadget.jsf endpoint with parameters referencing external URLs; outbound HTTP connections from the GlassFish server to attacker-controlled hosts (used to fetch malicious XML files); unexpected outbound connections on non-standard ports (reverse shell activity).
  • Logs: GlassFish access logs showing requests to /gadget.jsf or similar endpoints with external URL parameters; server-side EL evaluation errors or unexpected numeric outputs (e.g., 49) in application logs; authentication events from unfamiliar IP addresses against the admin console.
  • File System: Unexpected .xml files or web shells written to the GlassFish deployment or temp directories; new cron jobs, scheduled tasks, or startup scripts created by the GlassFish service account.
  • Process: Unusual child processes spawned by the GlassFish JVM process (e.g., bash, sh, cmd.exe, curl, wget, python, nc); unexpected network listeners opened by the GlassFish process (PoC GitHub, GitHub Advisory).

완화 및 해결 방법

Upgrade to Eclipse GlassFish 8.0.2 or later, which patches the vulnerable org.glassfish.main.admingui:admingui component, and upgrade org.glassfish.jsftemplating:jsftemplating to version 4.2.0 or later (GitHub Advisory, GlassFish Release). As interim mitigations: restrict network access to the GlassFish admin console (port 4848) to trusted IP ranges only; implement WAF rules to block EL injection patterns (e.g., #{, ${) in HTTP request parameters; disable EL evaluation in template contexts where user input is present if not required for functionality; and apply strict input validation and output encoding for all user-supplied values processed by the template rendering engine.

커뮤니티 반응

The vulnerability was noted in the OmniFish blog covering GlassFish 8.0.2's security fixes shortly after disclosure (OmniFish Blog). CISA included it in their weekly vulnerability bulletin (SB26-145), indicating recognition by the U.S. cybersecurity authority (CISA Bulletin). Community discussion was observed on Bluesky and security aggregator sites, and the vulnerability was featured in a PoC-of-the-week roundup in early June 2026 (PoC Week). Overall community sentiment reflects concern given the critical CVSS score and public PoC availability, though no widespread exploitation has been confirmed.

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 Java 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-10050HIGH8.7
  • Java logoJava
  • kafka-4.0
아니요Jul 22, 2026
GHSA-v74w-7mr3-4qg3HIGH7.5
  • Java logoJava
  • io.netty:netty-codec-xml
아니요Jul 24, 2026
CVE-2026-59949MEDIUM6.5
  • Java logoJava
  • at.yawk.lz4:lz4-java
아니요Jul 24, 2026
GHSA-mfg7-5gfp-c4w3MEDIUM5.3
  • Java logoJava
  • io.netty:netty-codec-dns
아니요Jul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • github.com/aws/aws-cdk-go/awscdk/v2
아니요Jul 24, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자