CVE-2026-92082

EUVD-2026-78575
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PayaraCNA
6.3 MEDIUM
ADJACENT
LOW
NONE
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
payarapayara
7.0.0 ≤
𝑥
< 7.2.0
CNA
payarapayara
7.2025.1 ≤
𝑥
< 7.2026.7
CNA
payarapayara
6.0.0 ≤
𝑥
< 6.40.0
CNA
payarapayara
5.20.0 ≤
𝑥
< 5.89.0
CNA
payarapayara
4.1.144 ≤
𝑥
< 4.1.2.191.57
CNA
payarapayara
6.2023.1
CNA
payarapayara
5.2020.1
CNA