Improper Input Validation Vulnerability in Pega Platform by Pegasystems
CVE-2026-13761

8.8HIGH

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-13761?

The Pega Platform has a vulnerability that stems from improper validation of input used for loop control conditions. This can result in excessive looping, potentially leading to a denial of service as the system becomes unresponsive under certain conditions. Organizations using affected versions should apply the necessary patches or mitigating solutions as outlined in the Pegasystems security advisory to secure their applications.

Affected Version(s)

Pega Infinity 7.1.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Barbaccia and Davide Bresaola from HWG Sababa
.