CVE-2026-92082
Received Received - Intake

Brute Force Login Vulnerability in Payara Server

Vulnerability report for CVE-2026-92082, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Payara

Description

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, seeΒ  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
payara payara_server *
azul payara 7.2.0
azul payara 7.2026.7
azul payara 6.40.0
azul payara 4.1.2.191.57
azul payara 5.89.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Payara Server lacking limits on failed login attempts by default, making it susceptible to brute force attacks. Automatic attack protection is available but requires configuration.

Detection Guidance

To detect this vulnerability, monitor failed login attempts on Payara Server. Check server logs for repeated authentication failures. Enable and review the built-in automatic attack protection logs as described in the security guide.

Impact Analysis

Attackers could gain unauthorized access to the server by repeatedly guessing credentials, potentially compromising sensitive data or system integrity.

Compliance Impact

The vulnerability allows brute force login attacks due to lack of failed login attempt limits, which could lead to unauthorized access. This may violate compliance requirements for data protection and access control under standards like GDPR (data security) and HIPAA (access controls).

Mitigation Strategies

Enable Payara Server's built-in automatic attack protection to limit failed login attempts. Configure the system security settings as described in the official Payara Server security guide.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92082. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart