CVE-2019-16374: Pega Platform

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

Affected products

  • Pega Platform: up to and including 8.2.1

Published 2020-08-13. Last modified 2026-06-17.