Junglewise Threat Intelligence

CVE-2025-62180: Pegasystems Pega Platform authorization bypass via crafted URLs

CVE-2025-62180 · Severity: info · CVSS 7.1 · Published 2026-06-23

Technologies: Pegasystems Pega Platform. Vendors: Pegasystems.

Executive brief

The Pega Platform, a popular enterprise software suite for workflow automation and customer engagement, contains a security flaw in its authorization system. An authenticated user could bypass intended access controls by using specially crafted web addresses (URLs) to view sensitive data they are not authorized to see. This could lead to the unauthorized exposure of internal business information or customer records.

Technical details

An authorization weakness (CWE-639: Authorization Bypass Through User-Controlled Key) exists in Pega Platform versions 8.3.0 through Infinity 25.1.2. The vulnerability allows a network-based attacker with low-level authenticated privileges to access or execute functions without proper authorization by manipulating URL parameters. This can result in high confidentiality impact as attackers may retrieve data outside of their assigned permissions. The issue is addressed in Pega Infinity 25.1.3 and various hotfixes for older versions (e.g., HFIX-D554, HFIX-D589). Pega Cloud environments are being proactively patched by the vendor.

Affected products

  • Pegasystems Pega Platform / Pega Infinity 8.3.0 through 25.1.2

Timeline

  • 2025-11-19: advisory: Initial remediation note published for I25 vulnerability series
  • 2026-06-22: advisory: Updated remediation note published for H26 vulnerability series
  • 2026-06-23: disclosed: CVE-2025-62180 published to NVD

References

Related threats