Cryptographic Signature Validation Flaw in Pega Platform by Pega Systems
CVE-2026-10754
8.6HIGH
What is CVE-2026-10754?
An issue has been identified in the Pega Platform where versions 8.5.0 through 25.1.2 suffer from improper validation of cryptographic signatures. This vulnerability could enable attackers to bypass existing security mechanisms, potentially leading to unauthorized access or manipulation of data. It is crucial for organizations using affected versions to assess their security posture and implement the necessary patches or mitigations to safeguard their systems.
Affected Version(s)
Pega Infinity 8.5.0
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yannick Scheepers, independent ethical hacker/security researcher
