Impact
The Pega Platform versions 8.5.0 through 25.1.2 contain an improper validation of cryptographic signatures that may allow an attacker to bypass built‑in security controls. This flaw is identified as a signature validation weakness (CWE‑347). The description does not specify additional confidentiality, integrity, or availability consequences, so those impacts are considered inferred and not asserted as factual.
Affected Systems
Pegasystems Pega Infinity platform versions 8.5.0 through 25.1.2 are affected.
Risk and Exploitability
The flaw has a CVSS score of 8.6, reflecting high severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly detailed in the advisory; the likely vector would be remote if the platform processes externally supplied signed content, based on the nature of a signature validation flaw.
OpenCVE Enrichment