7.3
CVE-2026-12986
- EPSS 0.18%
- Veröffentlicht 24.06.2026 14:08:02
- Zuletzt bearbeitet 25.06.2026 20:11:34
- Quelle 769c9ae7-73c3-4e47-ae19-903170
- CVE-Watchlists
- Unerledigt
A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Side Request Forgery (SSRF) vulnerability in the DownloadServlet of the Admin GUI in Payara Server allows a remote attacker to exfiltrate the administrator's REST session token (gfresttoken) to an attacker-controlled host via a crafted request URL. Combined with the absence of CSRF protection on DownloadServlet, an unauthenticated attacker can trick a logged-in administrator into triggering the token leak, then replay the stolen token to gain full administrative access to the Payara domain, leading to arbitrary code execution via WAR deployment. The vulnerability exists in the DownloadServlet and associated ContentSource implementations (LogViewerContentSource, LogFilesContentSource, LBConfigContentSource, ClientStubsContentSource) within the admingui:console-common module.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPayara
≫
Produkt
Payara Server
Default Statusaffected
Version
7.2025.1
Version <
7.2026.6
Status
affected
Version
7.0.0
Version <
7.1.0
Status
affected
Version
6.0.0
Version <
6.39.0
Status
affected
Version
5.20.0
Version <
5.88.0
Status
affected
Version
4.1.144
Version <
4.1.2.191.56
Status
affected
Version <=
5.201.2
Version
5.181
Status
affected
Version <=
5.2022.5
Version
5.2020.1
Status
affected
Version <=
6.2025.11
Version
6.2023.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 769c9ae7-73c3-4e47-ae19-903170fc3eb8 | 7.3 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Amber
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%207.2026.6.html