CVE-2026-92082 PUBLISHED

Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts

Assigner: Payara
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
CVSS Score: 6.3

Product Status

Vendor Payara
Product Payara Server
Versions Default: affected
  • affected from 7.0.0 to 7.2.0 (excl.)
  • affected from 7.2025.1 to 7.2026.7 (excl.)
  • affected from 6.0.0 to 6.40.0 (excl.)
  • affected from 5.20.0 to 5.89.0 (excl.)
  • affected from 4.1.144 to 4.1.2.191.57 (excl.)
  • Version 6.2023.1 is affected
  • Version 5.2020.1 is affected

References

Problem Types

  • CWE-307 Improper restriction of excessive authentication attempts CWE

Impacts

  • CAPEC-49 Password Brute Forcing
  • CAPEC-16 Dictionary-based Password Attack
  • CAPEC-565 Password Spraying
  • CAPEC-600 Credential Stuffing