Plattform
other
Komponente
pega-platform
Behoben in
25.1.2
CVE-2026-1564 describes an HTML Injection vulnerability discovered within the Pega Platform. This flaw allows an attacker, possessing a high privileged user account with a developer role, to inject malicious HTML into the application. The vulnerability affects versions 8.1.0 through 25.1.1 of the Pega Platform, and a patch is available in version Infinity 25.1.2.
Successful exploitation of CVE-2026-1564 could allow an attacker to inject arbitrary HTML into the Pega Platform user interface. This could be leveraged to execute malicious JavaScript code in the context of a victim's browser, leading to XSS attacks. An attacker could potentially steal session cookies, redirect users to phishing sites, or deface the application. The requirement for a high-privileged developer role limits the immediate blast radius, but a compromised developer account could provide access to sensitive data and configuration settings within the Pega Platform environment. This vulnerability highlights the importance of robust input validation and output encoding within web applications, especially those handling user-supplied data.
CVE-2026-1564 was published on 2026-04-15. Currently, there are no publicly known exploits or active campaigns targeting this vulnerability. Its exploitation probability is considered low due to the requirement for a high-privileged developer role. It is not listed on KEV or EPSS. Monitor security advisories and threat intelligence feeds for any updates regarding exploitation attempts.
Exploit-Status
EPSS
0.06% (18% Perzentil)
CISA SSVC
The primary mitigation for CVE-2026-1564 is to upgrade Pega Platform to version Infinity 25.1.2 or later, which includes the necessary fix. If immediate upgrading is not possible, consider implementing stricter input validation and output encoding on user-supplied data within the affected UI components. Web application firewalls (WAFs) configured to detect and block HTML injection attempts can provide an additional layer of defense. Regularly review user access controls and ensure that the principle of least privilege is enforced, limiting the number of users with developer roles. After upgrading, confirm the fix by attempting to inject HTML code into the affected UI component and verifying that it is properly sanitized.
Actualice Pega Platform a la versión 25.1.2 o posterior para mitigar la vulnerabilidad de inyección de HTML. Consulte la nota de remediación de seguridad de Pegasystems para obtener instrucciones detalladas sobre cómo aplicar la corrección y verificar la mitigación.
Schwachstellenanalysen und kritische Warnungen direkt in deinen Posteingang.
Pega Platform versions 8.1.0 through 25.1.1 are vulnerable.
A user with elevated privileges and a developer role.
Upgrade to Pega Infinity 25.1.2 or a later version.
Restrict access to development functions and carefully review user-provided data.
No, there is currently no KEV available.
Lade deine Abhängigkeitsdatei hoch und erfahre sofort, ob dich diese und andere CVEs treffen.