CVE-2026-92082 Details
Description
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
A vulnerability exists in Payara Server that allows brute force login attacks due to the absence of a default limit on failed login attempts. This weakness can be exploited by repeatedly attempting to log in with incorrect credentials. However, Payara Server provides built-in automatic protection against such attacks. For configuration details, refer to the Payara Server Security Guide.
To address this vulnerability, it is recommended to configure the built-in automatic attack protection feature in Payara Server. Instructions for doing so can be found in the Payara Server Security Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html | Payara | Release NotesVendor |
| https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html | Payara | Release NotesVendor |
| https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html | Payara | Release NotesVendor |
| https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html | Payara | Release NotesVendor |
| https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html | Payara | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | Payara |
Affected Products
| Product | Versions |
|---|---|
| Azul Payara Server | All versions |
CPE
Remediation
| |
| Azul Payara | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | New CVE Received | Payara |
| Sep 15, 2026 | CVE Modified | CISA-ADP |
Volerion