CVE-2026-92082
6.3
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
Summary
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Payara | Payara Server | 7.0.0 < 7.2.0 | affected |
| Payara | Payara Server | 7.2025.1 < 7.2026.7 | affected |
| Payara | Payara Server | 6.0.0 < 6.40.0 | affected |
| Payara | Payara Server | 5.20.0 < 5.89.0 | affected |
| Payara | Payara Server | 4.1.144 < 4.1.2.191.57 | affected |
| Payara | Payara Server | 6.2023.1 | affected |
| Payara | Payara Server | 5.2020.1 | affected |
Weaknesses
- CWE-307: CWE-307 Improper restriction of excessive authentication attempts
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html
- https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html
- https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html
- https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html
- https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.