THREATOPS
THREAT OPSThreat News › Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server

Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server

lowfulldisclosurePublished 2026-09-04

<p>Posted by Ron E on Sep 03</p>Payara Server exposes multiple HTTP-accessible EJB invocation mechanisms<br /> that rely on attacker-controlled reflection, dynamic class loading, and<br /> unsafe deserialization. These endpoints allow remote clients to perform<br /> arbitrary JNDI lookups, resolve attacker-supplied class names, and invoke<br /> EJB business methods via reflection without sufficien

Original source: https://seclists.org/fulldisclosure/2026/Sep/18