CVE-2026-10754
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Pegasystems | Pega Infinity | 8.5.0 < Infinity 25.1.3 | affected |
Weaknesses
- CWE-347: CWE-347: Improper Verification of Cryptographic Signature
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.