Description
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published: 2026-07-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected Cross‑Site Scripting flaw located in a user interface component of Pega Platform. When a high‑privileged user with a developer role interacts with, unsanitized input can be reflected back into a web page, enabling the injection of arbitrary JavaScript. This can lead to client‑side code execution and compromise the confidentiality, integrity, or availability of the information processed by the affected system for the user or anyone who views the crafted response.

Affected Systems

Pegasystems Pega Infinity, versions 8.1.0 through 25.1.2.

Risk and Exploitability

a CVSS score of 4.8 indicates moderate severity; the exploit requires a user with a high‑privileged developer role, limiting the attacker’s opportunities. The EPSS score is below 1%, suggesting a low probability of exploitation in current threat landscapes, and the vulnerability is not listed in CISA KEV. Nevertheless, if an attacker compromises or coerces such a privileged user, the reflected XSS can lead to client‑side code execution within the affected interface, potentially allowing the attacker to hijack the user’s session or manipulate web content for that user.

Generated by OpenCVE AI on July 31, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pega Platform to a version beyond 25.1.2, or apply the vendor’s latest security patch that addresses the XSS issue.
  • If an immediate upgrade is not possible, restrict or remove the high‑privileged developer role from users who do not require access to the affected component, and audit usage of the output encoding for the vulnerable UI component, following best practices for preventing XSS, such as using context‑aware escaping and Content Security Policy headers according to the vendor’s guidance.
  • Review and confirm that the vulnerable UI component’s output encoding logic strictly follows context‑aware escaping guidelines for XSS mitigation, and verify the implementation aligns with the vendor’s security recommendations for handling user input.

Generated by OpenCVE AI on July 31, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Pegasystems
Pegasystems pega Infinity
Vendors & Products Pegasystems
Pegasystems pega Infinity

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Title Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pegasystems Pega Infinity
cve-icon MITRE

Status: PUBLISHED

Assigner: Pega

Published:

Updated: 2026-07-15T18:12:40.935Z

Reserved: 2026-01-28T19:59:24.829Z

Link: CVE-2026-1563

cve-icon Vulnrichment

Updated: 2026-07-15T18:12:38.089Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')