Local Privilege Escalation in Pega Robotics by Pegasystems
CVE-2023-26466

7.8HIGH

Key Information:

Vendor
CVE Published:
10 April 2023

What is CVE-2023-26466?

A local privilege escalation vulnerability exists in Pega Robotics allowing a user with non-Admin access to modify a configuration file on the client side. This alteration permits the unauthorized change of the Server URL, potentially leading to significant security implications. Organizations using affected products should implement necessary measures to secure their configuration settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

RPA: Synchronization Engine 3.1.1

RPA: Synchronization Engine < 3.1.28

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Skyler Knecht and William Martin from the Adversarial Security Practice at Navy Federal Credit Union
.