Description
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published: 2026-08-04
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pega Platform versions 23.1.0 through 25.1.3 contain a stored cross‑site scripting flaw in a user interface component. The flaw requires a user with high privileged developer role to inject malicious script data that is later rendered in the browser of other users. Successful exploitation could allow an attacker to execute arbitrary JavaScript in the victim’s browser, potentially enabling session hijacking, credential theft, or defacement.

Affected Systems

Pegasystems Pega Infinity is affected. The vulnerability spans releases 23.1.0 to 25.1.3. No other vendors or products were identified in the CNA data.

Risk and Exploitability

CVSS score of 4.6 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Attack requires a developer role, limiting the attack surface to users with that role. Because the flaw resides in a UI component, exploitation generally requires manual injection by a developer; it is unlikely to be automated without privileged access.

Generated by OpenCVE AI on August 4, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Pega Infinity update that eliminates the stored XSS, following the remediation note from Pegasystems.
  • If an update cannot be applied immediately, restrict or remove the developer role from users who do not require it and disable the affected UI component if possible.
  • Ensure that all user‑supplied content rendered in the affected UI component is properly encoded or sanitized to prevent the execution of injected scripts.

Generated by OpenCVE AI on August 4, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Pegasystems
Pegasystems pega Infinity
Vendors & Products Pegasystems
Pegasystems pega Infinity

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Title Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pegasystems Pega Infinity
cve-icon MITRE

Status: PUBLISHED

Assigner: Pega

Published:

Updated: 2026-08-04T18:00:09.856Z

Reserved: 2026-07-01T13:14:37.060Z

Link: CVE-2026-14337

cve-icon Vulnrichment

Updated: 2026-08-04T18:00:05.199Z

cve-icon NVD

Status : Received

Published: 2026-08-04T14:16:30.470

Modified: 2026-08-04T19:16:42.020

Link: CVE-2026-14337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')