CVE-2025-14340
Received
Received - Intake
Cross-Site Scripting in Payara REST Interface Enables Admin Password Change
Publication date: 2026-02-18
Last updated on: 2026-02-18
Assigner: Payara
Description
Description
Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0,Β <6.34.0,Β <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| payara | server | to 7.2026.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |