CVE-2025-62182: Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
Published Jan 13, 2026
·Updated
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
Affected Software
1 affected component
Pega Customer Service Framework>=8.7.0<=25.1.0
Event History
Jan 13, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62182?
CVE-2025-62182 is considered a high severity vulnerability due to its potential for unauthorized file uploads.
2
How do I fix CVE-2025-62182?
To fix CVE-2025-62182, upgrade the Pega Customer Service Framework to a version above 25.1.0.
3
Who is affected by CVE-2025-62182?
CVE-2025-62182 affects users of Pega Customer Service Framework versions 8.7.0 through 25.1.0.
4
What type of vulnerability is CVE-2025-62182?
CVE-2025-62182 is an Unrestricted file upload vulnerability that allows privileged users to upload malicious files.
5
What are the potential consequences of CVE-2025-62182?
The potential consequences of CVE-2025-62182 include unauthorized access and execution of malicious files by attackers.