Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
Affected products
Payara · Payara ServerReferences
https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.htmlhttps://docs.azul.com/payara/release-notes/release-notes-7.2.0.htmlhttps://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.htmlhttps://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.htmlhttps://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html