PT-2026-51821 · Payara · Payara Server Full
CVSS v4.0
7.3
High
| Vector | AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Amber |
Name of the Vulnerable Software and Affected Versions
Payara Server Full versions 4.x
Payara Server Full versions 5.x
Payara Server Full versions 6.x
Payara Server Full versions 7.x
Payara Server Full versions 7.2026.x
Payara Server Full versions 6.2025.x
Payara Server Full versions 6.2024.x
Description
A Server-Side Request Forgery (SSRF) issue exists in the
DownloadServlet of the Admin GUI within the admingui:console-common module. This flaw, combined with a lack of Cross-Site Request Forgery (CSRF) protection on the DownloadServlet, allows a remote attacker to trick an authenticated administrator into sending their REST session token gfresttoken to an external host. An attacker can then use this stolen token to gain full administrative access to the domain, potentially leading to arbitrary code execution through the deployment of a WAR file. The issue affects the DownloadServlet and the following ContentSource implementations: LogViewerContentSource(), LogFilesContentSource(), LBConfigContentSource(), and ClientStubsContentSource().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Payara Server Full