CVE-2026-12986: CSRF

Published Jun 24, 2026
·
Updated

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain.

A Server-Side Request Forgery (SSRF) vulnerability in the DownloadServlet of the Admin GUI in Payara Server allows a remote attacker to exfiltrate the administrator's REST session token (gfresttoken) to an attacker-controlled host via a crafted request URL. Combined with the absence of CSRF protection on DownloadServlet, an unauthenticated attacker can trick a logged-in administrator into triggering the token leak, then replay the stolen token to gain full administrative access to the Payara domain, leading to arbitrary code execution via WAR deployment. The vulnerability exists in the DownloadServlet and associated ContentSource implementations (LogViewerContentSource, LogFilesContentSource, LBConfigContentSource, ClientStubsContentSource) within the admingui:console-common module.

Affected Software

1 affected component
Payara Payara Server Full>=4.0.0<5.0.0, >=5.0.0<6.0.0, >=6.0.0<7.0.0, >=7.0.0<8.0.0, >=7.2026.0<7.2027.0, >=6.2025.0<6.2026.0, >=6.2024.0<6.2025.0

Event History

Jun 24, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-12986?

CVE-2026-12986 has a severity score of 92, indicating it is a critical vulnerability.

2

How do I fix CVE-2026-12986?

To fix CVE-2026-12986, update your Payara Server Full to the latest version provided by the vendor.

3

What types of attacks are possible due to CVE-2026-12986?

CVE-2026-12986 allows for a full unauthenticated takeover of the Payara admin domain through gfresttoken leakage.

4

Which versions of Payara Server are affected by CVE-2026-12986?

CVE-2026-12986 affects Payara Server Full versions 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, and 6.2024.x.

5

What is the primary cause of CVE-2026-12986?

CVE-2026-12986 is primarily caused by vulnerabilities related to CSRF and SSRF in the Admin GUI.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203