CVE-2026-13761

8.8

Pegasystems · Pega Infinity

Pega Platform versions 7.1.0 through 25.1.2 contain an input validation flaw in loop conditions that can result in a denial of service.

Executive summary

An improper input validation vulnerability in Pega Infinity allows an unauthenticated attacker to trigger a denial of service via excessive looping.

Vulnerability

This vulnerability (CWE-606) involves improper validation of inputs used for loop conditions within the Pega Platform. An unauthenticated attacker can supply crafted input to trigger excessive looping, leading to service degradation or complete denial of service.

Business impact

The flaw carries a CVSS score of 8.8, reflecting its significant potential for service disruption. Successful exploitation could result in system downtime, preventing legitimate users from accessing critical enterprise workflows and impacting operational continuity.

Remediation

Immediate Action: Upgrade to Pega Infinity version 25.1.3 or later to apply the necessary input validation patches.

Proactive Monitoring: Monitor system performance metrics for sudden spikes in CPU or memory usage, which may indicate an attempt to trigger excessive loop conditions.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and inspect incoming requests for suspicious or malformed inputs that deviate from expected application behavior.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the ease of exploitation, organizations running affected versions of Pega Infinity must prioritize the update to version 25.1.3. Implementing the vendor patch is the only effective way to neutralize the risk of denial of service attacks against this platform.

More Pegasystems CVEs

Sources

Originally found and disclosed by Marco Barbaccia and Davide Bresaola from HWG Sababa, per the CVE Program record.