CVE Database
/

CVE-2025-14340

Back to search

CVE-2025-14340

Published: Feb 18, 2026

Modified: Feb 19, 2026

PUBLISHED

Description

Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.

VendorProductVersions

Payara Platform

Payara Server

affected
4.1.153.1 - <= 4.1.2.191.53
affected
5.20.0 - <= 5.82.0
affected
6.0.0 - <= 6.33.0
affected
7.2024.1.Alpha1 - <= 7.2025.2
affected
6.2022.1 - <= 6.2025.11

+6 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now