CVE Explorer
CVE-2026-12986
A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain.
A Server-Side Request Forgery (SSRF) vulnerability in the DownloadServlet of the Admin GUI in Payara Server allows a remote attacker to exfiltrate the administrator's REST session token (gfresttoken) to an attack
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-918","description":"CWE-918 Server-Side request forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-352","description":"CWE-352 Cross-Site request forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"affected","modules":["Admin GUI"],"packageName":"org.glassfish.main.admingui:console-common","platforms":["Windows","Linux","MacOS"],"product":"Payara Server","repo":"https://github.com/payara/Payara/","vendor":"Payara","versions":[{"lessThan":"7.2026.6","status":"affected","version":"7.2025.1","versionType":"custom"},{"lessThan":"7.1.0","status":"affected","version":"7.0.0","versionType":"semver"},{"lessThan":"6.39.0","status":"affected","version":"6.0.0","versionType":"semver"},{"lessThan":"5.88.0","status":"affected","version":"5.20.0","versionType":"semver"},{"lessThan":"…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"YES","Recovery":"USER","Safety":"PRESENT","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":7.3,"baseSeverity":"HIGH","exploitMaturity":"PROOF_OF_CONCEPT","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/S:P/AU:Y/R:U/V:C/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnCon…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-918","description":"CWE-918 Server-Side request forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-352","description":"CWE-352 Cross-Site request forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["release-notes"],"url":"https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%207.2026.6.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8bc274e569e6d3197958ab39942b83fbbedec0853ec5b1a27bfb628e3cd75760 · sha256:85a35ea28f9653af… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.