CVE-2026-92082

Summary

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

Affected Software

VendorProductVersion RangeStatus
PayaraPayara Server7.0.0 < 7.2.0affected
PayaraPayara Server7.2025.1 < 7.2026.7affected
PayaraPayara Server6.0.0 < 6.40.0affected
PayaraPayara Server5.20.0 < 5.89.0affected
PayaraPayara Server4.1.144 < 4.1.2.191.57affected
PayaraPayara Server6.2023.1affected
PayaraPayara Server5.2020.1affected

Weaknesses

  • CWE-307: CWE-307 Improper restriction of excessive authentication attempts

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References