Impact
Payara Server’s default configuration allows an unlimited number of failed login attempts. This means an attacker can repeatedly try credential combinations without interruption, potentially gaining administrative access. The weakness is a classic authentication bypass and is classified as CWE‑307. Successful exploitation would give the attacker full control over the deployed services, compromising confidentiality, integrity, and availability of the application environment.
Affected Systems
All Payara Server installations that have not been updated to a release with the built‑in automatic attack protection enabled are vulnerable. The CNA vendor list includes "Payara:Payara Server" with no specific version constraints in the official advisory, but newer release notes (7.2.0, 6.40.0,, and 4.1.2.191.57) reference the mitigation features.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate‑severity flaw. The EPSS score of < 1% indicates a very low likelihood that this vulnerability will be actively exploited, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. The likely attack vector is remote network access to the server’s administration interfaces. Because there is no account lockout mechanism, an attacker only needs network connectivity and persists with credential guessing, which is feasible with automated tools.
OpenCVE Enrichment