SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-92082

MEDIUM · CVSS 6.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Payara Server is vulnerable to brute force login attacks due to the lack of default limitations on failed login attempts. This can lead to unauthorized access if exploited. Organizations using Payara Server should prioritize addressing this vulnerability by implementing the built-in automatic attack protection features to enhance their security posture.

CVE
CVE-2026-92082
Severity
MEDIUM
CVSS
6.3
EPSS
0.19%

Original NVD Description

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, seeĀ  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .