Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html . | |
| Title | Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Payara
Published:
Updated: 2026-09-15T14:04:25.241Z
Reserved: 2026-09-15T13:03:29.440Z
Link: CVE-2026-92082
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-307
Improper Restriction of Excessive Authentication Attempts