CVE-2023-26466: High severity Pega Synchronization Engine vulnerability
Published Apr 10, 2023
·Updated
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
Affected Software
1 affected component
Pega Synchronization Engine>=3.1.1<3.1.30
Event History
Apr 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-26466?
The severity of CVE-2023-26466 is high with a severity value of 7.8.
2
How can a user with non-Admin access modify the Server URL in CVE-2023-26466?
A user with non-Admin access can change a configuration file on the client to modify the Server URL in CVE-2023-26466.
3
Which software is affected by CVE-2023-26466?
The Pega Synchronization Engine with versions between 3.1.1 and 3.1.30 is affected by CVE-2023-26466.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-26466?
The Common Weakness Enumeration (CWE) for CVE-2023-26466 is CWE-285.
5
Where can I find more information about CVE-2023-26466?
You can find more information about CVE-2023-26466 at this reference: https://support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege.