---
id: CVE-2026-92082
title: >-
  By default, Payara Server does not limit the number of failed login attempts,
  which can leave it vulnerable to brute force login attacks
summary: >-
  By default, Payara Server does not limit the number of failed login attempts,
  which can leave it vulnerable to brute force login attacks. To mitigate this,
  Payara Server includes built-in automatic attack protection. For configuration
  de…
severity: medium
cvss: 6.3
cvssVector: >-
  CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber
cwe:
  - CWE-307
vendor: Payara
product: org.glassfish.admingui.common.security
affected:
  - org.glassfish.admingui.common.security >= 7.0.0 < 7.2.0
  - org.glassfish.admingui.common.security >= 7.2025.1 < 7.2026.7
  - org.glassfish.admingui.common.security >= 6.0.0 < 6.40.0
  - org.glassfish.admingui.common.security >= 5.20.0 < 5.89.0
  - org.glassfish.admingui.common.security >= 4.1.144 < 4.1.2.191.57
  - org.glassfish.admingui.common.security 6.2023.1
  - org.glassfish.admingui.common.security 5.2020.1
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:32:26.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92082'
references:
  - url: >-
      https://docs.azul.com/payara-community/release-notes/release-notes-7.2026.7.html
    label: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
  - url: 'https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html'
    label: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
  - url: >-
      https://docs.azul.com/payara/version/4/release-notes/release-notes-4.1.2.191.57.html
    label: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
  - url: >-
      https://docs.azul.com/payara/version/5/release-notes/release-notes-5.89.0.html
    label: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
  - url: >-
      https://docs.azul.com/payara/version/6/release-notes/release-notes-6.40.0.html
    label: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
tags:
  - nvd
  - cve.org
epss: 0.00192
epssPercentile: 0.09095
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:58:27.927898Z'
cvssSource: cna
ingestedAt: '2026-09-15T14:38:16.205Z'
---

## Overview

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see  https://docs.azul.com/payara/technical-documentation/payara-server-documentation/security-guide/administering-system-security.html .

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
