Payara 7.2026.1.RC1 Arbitrary ... Note

Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server

Posted by Ron E on Sep 03Payara Server exposes multiple HTTP-accessible EJB invocation mechanisms that rely on attacker-controlled reflection, dynamic class loading, and unsafe deserialization. These endpoints allow remote clients to perform arbitrary JNDI lookups, resolve attacker-supplied class names, and invoke EJB business methods via reflection without sufficient authorization enforcement or input restriction. Both the deprecated InvokeEJBServlet and the...