Junglewise Threat Intelligence

CVE-2026-13761: Pegasystems Pega Platform improper validation of loop condition inputs

CVE-2026-13761 · Severity: info · CVSS 8.7 · Published 2026-08-28

Technologies: Pegasystems Pega Platform. Vendors: Pegasystems.

Executive brief

Pega Platform, a widely-used business process management and low-code development suite, contains a flaw in input validation for loop conditions. An attacker could exploit this to cause excessive looping, leading to denial of service and potential operational outages for organizations relying on Pega for critical business processes.

Technical details

The vulnerability is an improper validation of inputs used for loop conditions (CWE-690 / loop-related input validation failure). The flaw affects Pega Platform versions 7.1.0 through 25.1.2. Without proper bounds checking on loop condition inputs, an attacker can provide specially crafted input that triggers excessive iteration, exhausting system resources and causing denial of service. The attack vector is network-accessible if the affected component is exposed; no authentication bypass is required to trigger the excessive looping. Patches and hotfixes have been released for multiple version branches (23.1.5, 24.1.4, 24.2.5, 25.1.3+, 26.1).

Affected products

  • Pegasystems Pega Platform 7.1.0 through 25.1.2

Timeline

  • 2026-08-28: disclosed
  • 2026-06: patched: 24.2.5 patch release (June 2026); 26.1 release (July 2026); 25.1.4 targeted for October 2026

References

Related threats