Handing Your Token to a Stranger: SSRF + CSRF to Admin RCE in Payara Server (CVE-2026-12986)June 24, 2026 (3w ago)
A download servlet in Payara's admin console attaches the administrator's REST session token to an outbound request whose destination the caller controls, and it answers a plain GET with no CSRF token. Chained, an unauthenticated attacker lures a logged-in admin into leaking that token, replays it, and deploys a WAR for code execution as the server user. Fixed in Payara 7.2026.6.