Junglewise Threat Intelligence

CVE-2026-12986: Payara Server SSRF and CSRF in Admin GUI DownloadServlet

CVE-2026-12986 · Severity: high · CVSS 7.3 · Published 2026-06-24

Technologies: Payara Services Payara Server. Vendors: Payara Services, Maven.

Executive brief

A security vulnerability exists in the Payara Server administration console, a tool used to manage enterprise Java applications. An attacker can trick a logged-in administrator into visiting a malicious link, which causes the server to leak the administrator's secret session token. Using this stolen token, the attacker can take full control of the server, potentially allowing them to steal data or run unauthorized software on the corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the DownloadServlet component of the Payara Server Admin GUI, specifically within the admingui:console-common module. Due to a lack of CSRF protection on this servlet, an unauthenticated attacker can use social engineering to trick an authenticated administrator into making a crafted request. This request causes the server to exfiltrate the administrator's REST session token (gfresttoken) to an attacker-controlled host. The attacker can then replay this token to gain full administrative access, which facilitates arbitrary code execution via malicious WAR file deployment. The issue affects multiple ContentSource implementations including LogViewer, LogFiles, LBConfig, and ClientStubs.

Affected products

  • Payara Payara Server 4.x, 5.x, 6.x, 7.x (prior to 7.2026.6)

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory: NVD publication date

References