CVE-2026-92082
Received
Received - Intake
Brute Force Login Vulnerability in Payara Server
Vulnerability report for CVE-2026-92082, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-15
Assigner: Payara
Description
Description
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, seeΒ https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| payara | payara_server | * |
| azul | payara | 7.2.0 |
| azul | payara | 7.2026.7 |
| azul | payara | 6.40.0 |
| azul | payara | 4.1.2.191.57 |
| azul | payara | 5.89.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-307 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame. |