Executive brief
A security vulnerability exists in the Pega Platform, a suite used for business process management and customer engagement. An administrative user with extensive access rights could inject malicious scripts into the user interface, specifically within the Prediction Studio component. While the risk is categorized as low to medium because it requires high-level permissions to execute, it could potentially allow an attacker to view sensitive information within the user's session.
Technical details
A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in Pega Platform versions 8.1.0 through 25.1.0. The flaw is located within a user interface component, specifically affecting users with Pega Prediction Studio access. An attacker requires administrative privileges and extensive access rights to successfully inject malicious scripts. If exploited, the vulnerability allows for the execution of arbitrary JavaScript in the context of a victim's browser session, though the impact is limited to low confidentiality loss with no impact on integrity or availability. Remediation is available in Pega Platform patches 24.1.4, 24.2.4, and version 25.1.1.
Affected products
- Pegasystems Pega Platform 8.1.0 through 25.1.0
- Pegasystems Pega Infinity 8.1.0 through 25.1.0
Timeline
- 2026-03-16: advisory: Vendor advisory O25 published by Pegasystems
- 2026-03-31: disclosed: CVE-2025-62184 published to NVD