Description
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published: 2026-07-15
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stored cross‑site scripting flaw in a user interface component of Pega Platform. The flaw, identified as CWE‑79, allows a user with high privileged developer role to inject malicious scripts that persist in the system.

Affected Systems

Pegasystems Pega Infinity Platform versions 8.1.0 through 25.1.2.

Risk and Exploitability

The CVSS score of 4.6 classifies the risk as medium, while an EPSS score of <1% indicates a very low current exploitation likelihood. The vulnerability is not in the CISA KEV catalog. Exploitation requires possession of a high‑privileged developer account or compromise of such an account, so the attack vector is limited to users with those permissions. Because the payload runs in the victim’s browser, the threat is primarily directed at users who interact with the affected component, and the overall risk remains moderate.

Generated by OpenCVE AI on July 31, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Pega Platform patch or upgrade to a version that addresses the stored XSS issue as advised in Pega’s security advisory (https://support.pega.com/support-doc/pega-security-advisory-e26-vulnerability-remediation-note).
  • If a patch is unavailable, restrict the developer role to only the minimum necessary permissions and disable public editing of the affected component until remediation is applied.
  • Enable Content Security Policy and ensure all custom UI input is sanitized on the server side to mitigate injection risk if a future exploit emerges.

Generated by OpenCVE AI on July 31, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Pegasystems
Pegasystems pega Infinity
Vendors & Products Pegasystems
Pegasystems pega Infinity

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Title Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pegasystems Pega Infinity
cve-icon MITRE

Status: PUBLISHED

Assigner: Pega

Published:

Updated: 2026-07-15T18:13:03.446Z

Reserved: 2026-01-28T19:59:23.519Z

Link: CVE-2026-1562

cve-icon Vulnrichment

Updated: 2026-07-15T18:12:57.129Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')