CVE-2026-10754
8.6Pegasystems · Pega Infinity
Pega Infinity is affected by an improper verification of cryptographic signatures vulnerability, which allows authenticated attackers to potentially compromise data integrity and confidentiality.
Executive summary
A cryptographic signature verification flaw in Pega Infinity allows authenticated attackers to compromise system data, necessitating an immediate software update.
Vulnerability
This vulnerability, identified as CWE-347, involves the improper verification of cryptographic signatures. It requires an authenticated user to exploit the flaw, as indicated by the PR:L (Privileges Required: Low) vector.
Business impact
Successful exploitation allows an attacker with low-level privileges to bypass signature checks, which can lead to unauthorized data modification or access. With a CVSS score of 8.6, this vulnerability poses a significant risk to the integrity of business operations and the confidentiality of stored information within the Pega environment.
Remediation
Immediate Action: Upgrade Pega Infinity to version 25.1.3 or higher as specified in the vendor security advisory.
Proactive Monitoring: Monitor system access logs for unusual patterns involving administrative or sensitive data functions that rely on cryptographic verification.
Compensating Controls: Ensure that strict internal network segmentation and robust identity management policies are enforced to limit the potential impact of authenticated users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high severity of this vulnerability, administrators should prioritize the application of the vendor-provided security patches. Updating to the latest version of Pega Infinity is the only reliable method to eliminate the risk associated with this cryptographic implementation error.