๐Ÿ” CVE Alert

CVE-2026-92082

UNKNOWN 0.0

Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, seeย  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

CWE CWE-307
Vendor payara
Product payara server
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for payara payara server

Be the first to know when new unknown vulnerabilities affecting payara payara server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Payara / Payara Server
7.0.0 < 7.2.0 7.2025.1 < 7.2026.7 6.0.0 < 6.40.0 5.20.0 < 5.89.0 4.1.144 < 4.1.2.191.57 6.2023.1 5.2020.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.azul.com: https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html docs.azul.com: https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html docs.azul.com: https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html docs.azul.com: https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html docs.azul.com: https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html