Skip to content
PegasystemsCVE-2026-10754

Pegasystems Pega Infinity: improper signature check

High8.6CVE-2026-10754 · Published Aug 10, 2026 · updated Sep 8, 2026

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

Pegasystems advisory

Affected versions

PackageAffectedFixed in
Pega Infinity
Product
>= 8.5.0, < Infinity 25.1.3Infinity 25.1.3
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More Pegasystems advisories

All Pegasystems
Advisory
Pegasystems Pega Infinity: denial of service
High8.8Aug 28
Pegasystems Pega Infinity: cross-site scripting
Medium4.6Aug 4
Pegasystems Pega Infinity: cross-site scripting
Medium4.6Jul 15
Pegasystems Pega Infinity: cross-site scripting
Medium4.8Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.