Executive brief
Pega Platform, a widely-used business process management and low-code development suite, contains a flaw in input validation for loop conditions. An attacker could exploit this to cause excessive looping, leading to denial of service and potential operational outages for organizations relying on Pega for critical business processes.
Technical details
The vulnerability is an improper validation of inputs used for loop conditions (CWE-690 / loop-related input validation failure). The flaw affects Pega Platform versions 7.1.0 through 25.1.2. Without proper bounds checking on loop condition inputs, an attacker can provide specially crafted input that triggers excessive iteration, exhausting system resources and causing denial of service. The attack vector is network-accessible if the affected component is exposed; no authentication bypass is required to trigger the excessive looping. Patches and hotfixes have been released for multiple version branches (23.1.5, 24.1.4, 24.2.5, 25.1.3+, 26.1).
Affected products
- Pegasystems Pega Platform 7.1.0 through 25.1.2
Timeline
- 2026-08-28: disclosed
- 2026-06: patched: 24.2.5 patch release (June 2026); 26.1 release (July 2026); 25.1.4 targeted for October 2026