CVE-2026-12986

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Side Request Forgery (SSRF) vulnerability in the DownloadServlet of the Admin GUI in Payara Server allows a remote attacker to exfiltrate the administrator's REST session token (gfresttoken) to an attacker-controlled host via a crafted request URL. Combined with the absence of CSRF protection on DownloadServlet, an unauthenticated attacker can trick a logged-in administrator into triggering the token leak, then replay the stolen token to gain full administrative access to the Payara domain, leading to arbitrary code execution via WAR deployment. The vulnerability exists in the DownloadServlet and associated ContentSource implementations (LogViewerContentSource, LogFilesContentSource, LBConfigContentSource, ClientStubsContentSource) within the admingui:console-common module.


We have discovered 513 live websites that are affected by CVE-2026-12986.

Run a Free Instant Scan




Affected Software

Product  Payara Server
Category Web Servers
Vulnerable Domains513 live websites (67% of Payara Server install base)
Vulnerable Versions
  • from 4.1.144 through 4.1.2.191.56
  • from 5.20 through 5.88
  • from 5.181 through 5.201.2
  • from 5.2020.1 through 5.2022.5
  • from 6 through 6.39
  • from 6.2023.1 through 6.2025.11
  • from 7 through 7.1
  • from 7.2025.1 through 7.2026.6
Vulnerable Versions Count42 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jun 24, 2026
  • Updated - Jun 24, 2026

Website Distribution by Country

Number of websites using CVE-2026-12986
United States108 websites



Czech Republic88 websites
Germany61 websites
Brazil39 websites
France21 websites
Finland20 websites
Russia15 websites
Mexico11 websites
Canada11 websites
Italy10 websites

Website Distribution by TLD

Number of websites using CVE-2026-12986
.com105 websites
.eu59 websites
.net41 websites
.cz32 websites
.fr28 websites
.com.br26 websites
.fi19 websites
.de17 websites
.it16 websites
.ru14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12986

Top websites that are affected by CVE-2026-12986. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*********.com United States***,***
*******.*********.com United States***,***
*******.eu Czech Republic***,***
*********.ru Russia***,***
*******.ru Russia***,***
***********.com United States***,***
****.***********.be Belgium***,***
***.com Austria***,***
*******************.**.uk GB***,***
********************.net United States***,***
See full domain list

FAQ

CVE-2026-12986 is Cross-Site Request Forgery (CSRF) in Payara Server
A total of 513 websites have been identified as vulnerable to CVE-2026-12986, based on global website indexing conducted by WebTechSurvey.
The Payara Server is affected by the CVE-2026-12986 vulnerability.
Payara Server versions up to 7.2026.6 are vulnerable to CVE-2026-12986.
CVE-2026-12986 is resolved in version 7.2026.6 of Payara Server.