/Vulnerability Library

Payara Server - Cross-Site Scripting

CVE-2025-14340
Verified

Description

Payara Server versions <4.1.2.191.54, <5.83.0, <6.34.0, and <7.2026.1 contain a stored XSS vulnerability caused by improper input sanitization in the REST Management Interface. This allows attackers to mislead administrators into changing the admin password via a URL payload; however, the exploit requires administrator interaction.

Severity

High

CVSS Score

9

Exploit Probability

1%

Published Date

April 7, 2026

Template Author

0x_akoko, 0xr2r

CVE-2025-14340.yaml
9.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-14340
CWE ID:
cwe-79

References

https://github.com/DeepSecurityResearch/CVE-2025-14340https://www.payara.fishhttps://nvd.nist.gov/vuln/detail/CVE-2025-14340

Remediation Steps

Update to version 4.1.2.191.54, 5.83.0, 6.34.0, 7.2026.1 or later.