Description
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account access via brute‑force login
Action: Apply Patch
AI Analysis

Impact

Payara Server’s default configuration allows an unlimited number of failed login attempts. This means an attacker can repeatedly try credential combinations without interruption, potentially gaining administrative access. The weakness is a classic authentication bypass and is classified as CWE‑307. Successful exploitation would give the attacker full control over the deployed services, compromising confidentiality, integrity, and availability of the application environment.

Affected Systems

All Payara Server installations that have not been updated to a release with the built‑in automatic attack protection enabled are vulnerable. The CNA vendor list includes "Payara:Payara Server" with no specific version constraints in the official advisory, but newer release notes (7.2.0, 6.40.0,, and 4.1.2.191.57) reference the mitigation features.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate‑severity flaw. The EPSS score of < 1% indicates a very low likelihood that this vulnerability will be actively exploited, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. The likely attack vector is remote network access to the server’s administration interfaces. Because there is no account lockout mechanism, an attacker only needs network connectivity and persists with credential guessing, which is feasible with automated tools.

Generated by OpenCVE AI on September 17, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Payara Server release that includes the built‑in automatic attack protection; consult the referenced release notes for supported versions.
  • Enable and configure the automatic attack protection by following the guidance in the Payara security guide; this will enforce limits on failed login attempts and lock out accounts after repeated failures.
  • Review your deployment’s network exposure; restrict administrative access to trusted networks and apply additional rate‑limiting or firewall rules as an extra defense layer.

Generated by OpenCVE AI on September 17, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Payara
Payara payara Server
Vendors & Products Payara
Payara payara Server

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
Title Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts
Weaknesses CWE-307
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber'}


Subscriptions

Payara Payara Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Payara

Published:

Updated: 2026-09-15T14:58:50.917Z

Reserved: 2026-09-15T13:03:29.440Z

Link: CVE-2026-92082

cve-icon Vulnrichment

Updated: 2026-09-15T14:58:46.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:33.317

Modified: 2026-09-18T19:32:26.093

Link: CVE-2026-92082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:30:06Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts