PT-2026-51821 · Payara · Payara Server Full

·

CVE-2026-12986

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v4.0

7.3

High

VectorAV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Payara Server Full versions 4.x Payara Server Full versions 5.x Payara Server Full versions 6.x Payara Server Full versions 7.x Payara Server Full versions 7.2026.x Payara Server Full versions 6.2025.x Payara Server Full versions 6.2024.x
Description A Server-Side Request Forgery (SSRF) issue exists in the DownloadServlet of the Admin GUI within the admingui:console-common module. This flaw, combined with a lack of Cross-Site Request Forgery (CSRF) protection on the DownloadServlet, allows a remote attacker to trick an authenticated administrator into sending their REST session token gfresttoken to an external host. An attacker can then use this stolen token to gain full administrative access to the domain, potentially leading to arbitrary code execution through the deployment of a WAR file. The issue affects the DownloadServlet and the following ContentSource implementations: LogViewerContentSource(), LogFilesContentSource(), LBConfigContentSource(), and ClientStubsContentSource().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12986

Affected Products

Payara Server Full