Executive brief
Pega Platform, a widely-used enterprise application development and case management system, contains a flaw in its Session API that improperly validates cryptographic signatures. An attacker can forge or tamper with API requests to bypass security controls, potentially gaining unauthorized access to sensitive data or performing unauthorized actions within customer environments.
Technical details
The vulnerability exists in Pega Platform's Session API, where cryptographic signatures used to authenticate API requests are not properly validated. Insufficient checks fail to confirm that requests have been correctly signed and have not been altered in transit. The flaw affects versions from 8.5.0 through 25.1.2 and is exploitable over the network without authentication or user interaction. An attacker can forge or modify Session API requests to bypass security controls, potentially reading sensitive data or executing unauthorized actions. Patches are available: Platform releases 24.2.5, 25.1.3, and 26.1, or hotfixes for earlier versions (HFIX-D1442 through HFIX-D1443).
Affected products
- Pegasystems Pega Platform 8.5.0 through 25.1.2
Timeline
- 2026-08-10: disclosed: Security advisory published; patches released starting June 2026
- 2026-06-23: patched: 25.1.3 Patch Release available
- 2026-06-25: patched: 24.2.5 Patch Release available
- 2026-07-14: patched: 26.1 Patch Release available