CVE-2026-14337: Pegasystems Pega Infinity

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

Affected products

Published 2026-08-04. Last modified 2026-09-08.