CVE-2026-10754

8.6

Pegasystems · Pega Infinity

Pega Infinity is affected by an improper verification of cryptographic signatures vulnerability, which allows authenticated attackers to potentially compromise data integrity and confidentiality.

Executive summary

A cryptographic signature verification flaw in Pega Infinity allows authenticated attackers to compromise system data, necessitating an immediate software update.

Vulnerability

This vulnerability, identified as CWE-347, involves the improper verification of cryptographic signatures. It requires an authenticated user to exploit the flaw, as indicated by the PR:L (Privileges Required: Low) vector.

Business impact

Successful exploitation allows an attacker with low-level privileges to bypass signature checks, which can lead to unauthorized data modification or access. With a CVSS score of 8.6, this vulnerability poses a significant risk to the integrity of business operations and the confidentiality of stored information within the Pega environment.

Remediation

Immediate Action: Upgrade Pega Infinity to version 25.1.3 or higher as specified in the vendor security advisory.

Proactive Monitoring: Monitor system access logs for unusual patterns involving administrative or sensitive data functions that rely on cryptographic verification.

Compensating Controls: Ensure that strict internal network segmentation and robust identity management policies are enforced to limit the potential impact of authenticated users.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity of this vulnerability, administrators should prioritize the application of the vendor-provided security patches. Updating to the latest version of Pega Infinity is the only reliable method to eliminate the risk associated with this cryptographic implementation error.