CVE-2025-62182: Pegasystems Pega Infinity

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

Affected products

Published 2026-01-13. Last modified 2026-06-17.