ZeroHour
Full Disclosurepublished ()ingested
Part of a story covered by 2 sources: “Payara Server 7.2026.1.RC1: Arbitrary EJB Method Invocation via Insecure Reflection and OS Command Execution via SSI #exec Directive” — merged summary and timeline →

Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server

highVulnerabilityimportance 35
AI summary · glm-5.3-flash

Payara Server 7.2026.1.RC1 executes arbitrary OS commands when user-controlled Server-Side Includes #exec directives are passed to Runtime.exec without validation.

Payara Server contains a vulnerability in its Server-Side Includes (SSI) implementation that permits arbitrary operating system command execution via the #exec directive. User-controlled SSI directives are passed directly to Runtime.exec() without validation, sanitization, or restriction. An attacker who can cause the server to process an SSI file such as .shtml can execute arbitrary OS commands. The disclosed affected version is 7.2026.1.RC1.

  • User-controlled SSI #exec directives reach Runtime.exec() without sanitization
  • Affects processing of .shtml files on Payara Server 7.2026.1.RC1
  • Allows arbitrary operating system command execution
VendorsPayara
Full article

Posted by Ron E on Sep 03 *Description:* Payara Server contains a vulnerability in its Server-Side Includes (SSI) implementation that allows arbitrary operating system command execution via the #exec directive. The issue occurs because user-controlled SSI directives are passed directly to Runtime.exec() without validation, sanitization, or restriction. An attacker who can cause the server to process an SSI file (e.g., .shtml) can execute arbitrary OS commands with the...

This source does not provide full text. Read it at seclists.org.