CVE-2026-92082
EUVD-2026-7857515.09.2026, 15:17
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| payara | payara | 7.0.0 ≤ 𝑥 < 7.2.0 | CNA |
| payara | payara | 7.2025.1 ≤ 𝑥 < 7.2026.7 | CNA |
| payara | payara | 6.0.0 ≤ 𝑥 < 6.40.0 | CNA |
| payara | payara | 5.20.0 ≤ 𝑥 < 5.89.0 | CNA |
| payara | payara | 4.1.144 ≤ 𝑥 < 4.1.2.191.57 | CNA |
| payara | payara | 6.2023.1 | CNA |
| payara | payara | 5.2020.1 | CNA |
References