{"id":"CVE-2026-92082","title":"By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks","summary":"By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration de…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber","cwe":["CWE-307"],"vendor":"Payara","product":"org.glassfish.admingui.common.security","affected":["org.glassfish.admingui.common.security >= 7.0.0 < 7.2.0","org.glassfish.admingui.common.security >= 7.2025.1 < 7.2026.7","org.glassfish.admingui.common.security >= 6.0.0 < 6.40.0","org.glassfish.admingui.common.security >= 5.20.0 < 5.89.0","org.glassfish.admingui.common.security >= 4.1.144 < 4.1.2.191.57","org.glassfish.admingui.common.security 6.2023.1","org.glassfish.admingui.common.security 5.2020.1"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:32:26.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92082","references":[{"url":"https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html","label":"769c9ae7-73c3-4e47-ae19-903170fc3eb8"},{"url":"https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html","label":"769c9ae7-73c3-4e47-ae19-903170fc3eb8"},{"url":"https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html","label":"769c9ae7-73c3-4e47-ae19-903170fc3eb8"},{"url":"https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html","label":"769c9ae7-73c3-4e47-ae19-903170fc3eb8"},{"url":"https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html","label":"769c9ae7-73c3-4e47-ae19-903170fc3eb8"}],"tags":["nvd","cve.org"],"epss":0.00192,"epssPercentile":0.09109,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T14:58:27.927898Z"},"cvssSource":"cna","ingestedAt":"2026-09-15T14:38:16.205Z","slug":"CVE-2026-92082","body":"## Overview\n\nBy default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}