CVE-2026-92082
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
- EPSS probability
- 0.19%
- CWE
- CWE-307
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Payara Payara Server
- Payara Payara Server
- Payara Payara Server
- Payara Payara Server
- Payara Payara Server
- Payara Payara Server
- Payara Payara Server
Weakness type
Related vulnerabilities
- CVE-2025-64310 — EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp
- CVE-2026-32295 — JetKVM insufficient login rate limiting
- CVE-2026-32292 — GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting
- CVE-2025-46414 — EG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication Attempts
- CVE-2026-33640 — Outline has a rate limit bypass that allows brute force of email login OTP
- CVE-2026-33419 — MinIO: LDAP login brute-force via user enumeration and missing rate limit
- CVE-2026-33152 — Tandoor Recipes Vulnerable to Unrestricted Brute-Force via BasicAuthentication
- CVE-2026-31904 — CTEK Chargeportal Improper Restriction of Excessive Authentication Attempts