CVE-2026-10754: Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
Published Aug 10, 2026
·Updated
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
Affected Software
1 affected component
Pega Pega Platform>=8.5.0<=25.1.2
Event History
Aug 10, 2026
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-10754?
CVE-2026-10754 has a risk score of 60, indicating a medium level of severity.
2
How do I fix CVE-2026-10754?
To remediate CVE-2026-10754, it is recommended to upgrade Pega Platform to a version that is not affected, specifically above 25.1.2.
3
What type of vulnerability is CVE-2026-10754?
CVE-2026-10754 is classified as an improper validation of cryptographic signatures.
4
What versions of Pega Platform are impacted by CVE-2026-10754?
Pega Platform versions 8.5.0 through 25.1.2 are affected by CVE-2026-10754.
5
What potential exploit can occur due to CVE-2026-10754?
CVE-2026-10754 may allow an attacker to bypass security controls due to the improper validation of cryptographic signatures.