Home

Description

Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.

PUBLISHED Reserved 2025-12-09 | Published 2026-02-18 | Updated 2026-02-19 | Assigner Payara




HIGH: 7.3CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/S:P/AU:N/R:U/RE:M/U:Red

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

4.1.153.1 (custom)
affected

5.20.0 (semver)
affected

6.0.0 (semver)
affected

7.2024.1.Alpha1 (semver)
affected

6.2022.1 (semver)
affected

5.2020.2 (semver)
affected

5.181 (semver)
affected

4.1.2.191.54 (custom)
unaffected

5.83.0 (semver)
unaffected

6.34.0 (semver)
unaffected

7.2026.1 (semver)
unaffected

Credits

Camilo G. AkA Dédalo [https://x.com/SeguridadBlanca] (DeepSecurity Perú - [https://www.deepsecurity.pe]) reporter

References

docs.payara.fish/...ise/docs/Security/Security Fix List.html

cve.org (CVE-2025-14340)

nvd.nist.gov (CVE-2025-14340)

Download JSON