CVE-2026-0898: An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25.
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The vulnerability may be exploited if a Pega Robot Studio developer is deceived into visiting this website during interrogation mode in Robot Studio.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0898?
CVE-2026-0898 is classified as a high-severity vulnerability due to its potential for arbitrary file-writing.
How do I fix CVE-2026-0898?
To fix CVE-2026-0898, upgrade the Pega Browser Extension (PBE) and Pega Robot Studio to versions beyond 22.1 and R25.
Who is affected by CVE-2026-0898?
CVE-2026-0898 affects developers using Pega Robot Studio with the Pega Browser Extension on Google Chrome and Microsoft Edge in versions 22.1 and R25.
What are the implications of CVE-2026-0898?
The implications of CVE-2026-0898 include unauthorized file manipulation which can lead to data breaches and compromised system integrity.
When was CVE-2026-0898 published?
CVE-2026-0898 was published in 2026, highlighting a critical security concern in the Pega ecosystem.