Cryptographic Signature Validation Flaw in Pega Platform by Pega Systems
CVE-2026-10754

8.6HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-10754?

An issue has been identified in the Pega Platform where versions 8.5.0 through 25.1.2 suffer from improper validation of cryptographic signatures. This vulnerability could enable attackers to bypass existing security mechanisms, potentially leading to unauthorized access or manipulation of data. It is crucial for organizations using affected versions to assess their security posture and implement the necessary patches or mitigations to safeguard their systems.

Affected Version(s)

Pega Infinity 8.5.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yannick Scheepers, independent ethical hacker/security researcher
.