Brute Force Vulnerability in Payara Server
CVE-2026-92082

6.3MEDIUM

Key Information:

Vendor

Payara

Vendor
CVE Published:
15 September 2026

What is CVE-2026-92082?

The Payara Server is susceptible to a brute force login vulnerability, as it does not impose a limit on failed login attempts by default. This can lead to attackers exploiting this weakness through repeated login attempts to gain unauthorized access. To address this concern, Payara Server offers automatic attack protection features that can be configured to enhance security. Detailed guidance on how to implement these configurations can be found in the official Payara Server security documentation.

Affected Version(s)

Payara Server 7.0.0

Payara Server 7.0.0 < 7.2.0

Payara Server 7.2025.1 < 7.2026.7

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.