CVE-2025-14340: Payara Platform Payara Server

High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.

Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.

Affected products

  • Payara Platform Payara Server: from 4.1.153.1, up to and including 4.1.2.191.53; from 5.20.0, up to and including 5.82.0; from 6.0.0, up to and including 6.33.0; from 7.2024.1.Alpha1, up to and including 7.2025.2; from 6.2022.1, up to and including 6.2025.11; from 5.2020.2, up to and including 5.2022.5; …

Published 2026-02-18. Last modified 2026-06-17.