# CVE-2026-92082

## Summary

- **CVE ID:** CVE-2026-92082
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber)
- **CWE:** CWE-307
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

## Affected Products

- Payara — Payara Server (7.0.0)
- Payara — Payara Server (7.2025.1)
- Payara — Payara Server (6.0.0)
- Payara — Payara Server (5.20.0)
- Payara — Payara Server (4.1.144)
- Payara — Payara Server (6.2023.1)
- Payara — Payara Server (5.2020.1)

## References

- [CNA](https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html)
- [CNA](https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html)
- [CNA](https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html)
- [CNA](https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html)
- [CNA](https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._