CVE-2026-1562: Pega Platform
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Affected products
- Pega Pega Platform: from 8.1, before 24.2.4 (fixed in 24.2.4); from 25.1.0, before 25.1.3 (fixed in 25.1.3)
Published 2026-07-15. Last modified 2026-07-21.