CVE-2025-14340: Admin Account Takeover via malicious URL payload
Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability CVE-2025-14340?
CVE-2025-14340 is a cross-site scripting vulnerability in the REST Management Interface of the Payara Server that allows an attacker to take over admin accounts via a malicious URL payload.
What versions of Payara Server are affected by CVE-2025-14340?
Payara Server versions prior to 4.1.2.191.54, 5.83.0, 6.34.0, and 7.2026.1 are affected by CVE-2025-14340.
How can I fix CVE-2025-14340?
To fix CVE-2025-14340, upgrade your Payara Server to a version that is not vulnerable, specifically to version 4.1.2.191.54 or higher.
What are the potential impacts of CVE-2025-14340 on my system?
The potential impacts of CVE-2025-14340 include unauthorized access to admin accounts, which can lead to further compromise of the system.
Who should be concerned about CVE-2025-14340?
Administrators and users of affected Payara Server versions should be concerned about CVE-2025-14340 to prevent unauthorized account access.