CVE-2025-62180: Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
Published Jun 23, 2026
·Updated
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
Affected Software
1 affected component
Pegasystems Pega Platform>=8.3.0<=25.1.2
Event History
Jun 23, 2026
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62180?
CVE-2025-62180 has a high severity rating of 7.1.
2
How do I fix CVE-2025-62180?
To remediate CVE-2025-62180, update Pega Platform to versions beyond 25.1.2.
3
What types of systems are affected by CVE-2025-62180?
CVE-2025-62180 affects Pega Platform versions 8.3.0 through Infinity 25.1.2.
4
What is the nature of the vulnerability in CVE-2025-62180?
CVE-2025-62180 is an authorization weakness that permits authenticated users to access additional data through crafted URLs.
5
Can this vulnerability in CVE-2025-62180 be exploited remotely?
Yes, the vulnerability in CVE-2025-62180 can be exploited with network access by authenticated users.