← Vulnerability feed

Vulnerability record · CVE-2021-41381 · published 23 September 2021

CVE-2021-41381: Payara Micro Community directory traversal allows file read

Payara · Micro Community

Payara Micro Community 5.2021.6 and earlier is vulnerable to directory traversal (CWE-22), letting a remote unauthenticated attacker request files outside the intended web root. The flaw is trivially reachable over the network and public proof-of-concept code exists, so exposed instances should be treated as at risk of information disclosure.

7.5 CVSS 3.1 High EPSS 53% · top 1.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 4.3
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

Payara Micro Community 5.2021.6 and below allows Directory Traversal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated file read with public exploit code and a high EPSS score, though no KEV listing or evidence of active mass exploitation.

What it is

Payara Micro Community 5.2021.6 and earlier is vulnerable to directory traversal (CWE-22), letting a remote unauthenticated attacker request files outside the intended web root. The flaw is trivially reachable over the network and public proof-of-concept code exists, so exposed instances should be treated as at risk of information disclosure.

Impact

An attacker can read arbitrary files on the server that the Payara process can access, potentially exposing configuration, credentials and application data. There is no evidence in the record of code execution or data modification.

Attack surface

Reached over the network via HTTP requests to the affected Payara Micro Community service; the CVSS vector shows no privileges and no user interaction required. Any instance exposed to untrusted networks is directly reachable.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.529, ~98.9th percentile) and multiple references are tagged Exploit, including Exploit-DB and Packet Storm entries, indicating public exploit code is available.

What to do

  • Upgrade Payara Micro Community to a version later than 5.2021.6; the record does not name a fixed version, so confirm the patched release with the vendor.
  • If immediate upgrade is not possible, restrict network access to the Payara service with firewall rules or a reverse proxy that normalizes and rejects traversal sequences.
  • Run the service with least-privilege filesystem permissions so a traversal read cannot reach sensitive files.
  • Review the vendor advisory and SYSS-2021-054 for any configuration hardening guidance.
  • Monitor vendor channels for updated fixed versions since the record does not specify one.

Detection

  • Inspect web and proxy logs for requests containing ../, encoded traversal sequences (%2e%2e, ..%2f) or absolute paths targeting the Payara service.
  • Alert on HTTP responses returning files outside expected static content paths, especially configuration or credential files.
  • Baseline normal request URI patterns for the application and flag anomalies.
  • Correlate outbound or internal file access events from the Payara process with unusual request sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed6.5CVE-2026-20262Cisco Catalyst SD-WAN Manager path traversal in file uploadCisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal…KEVEPSS 28%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2021-41381), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.