CVE-2026-10754

8.6

Pegasystems · Pega Infinity

Pega Infinity is affected by an improper verification of cryptographic signatures vulnerability, which allows authenticated attackers to potentially compromise data integrity and confidentiality.

Executive summary

A cryptographic signature verification flaw in Pega Infinity allows authenticated attackers to compromise system data, necessitating an immediate software update.

Vulnerability

This vulnerability, identified as CWE-347, involves the improper verification of cryptographic signatures. It requires an authenticated user to exploit the flaw, as indicated by the PR:L (Privileges Required: Low) vector.

Business impact

Successful exploitation allows an attacker with low-level privileges to bypass signature checks, which can lead to unauthorized data modification or access. With a CVSS score of 8.6, this vulnerability poses a significant risk to the integrity of business operations and the confidentiality of stored information within the Pega environment.

Remediation

Immediate Action: Upgrade Pega Infinity to version 25.1.3 or higher as specified in the vendor security advisory.

Proactive Monitoring: Monitor system access logs for unusual patterns involving administrative or sensitive data functions that rely on cryptographic verification.

Compensating Controls: Ensure that strict internal network segmentation and robust identity management policies are enforced to limit the potential impact of authenticated users.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity of this vulnerability, administrators should prioritize the application of the vendor-provided security patches. Updating to the latest version of Pega Infinity is the only reliable method to eliminate the risk associated with this cryptographic implementation error.

More Pegasystems CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section