CVE-2020-15390: Pega Platform

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

Affected products

  • Pega Pega Platform: version 8.4.0.237 only

Published 2021-04-12. Last modified 2026-06-17.