CVE-2026-1078: An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge.
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime user navigates to the malicious website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1078?
CVE-2026-1078 has been classified as a high severity vulnerability due to its potential for arbitrary file write operations.
How do I fix CVE-2026-1078?
To fix CVE-2026-1078, users should upgrade to the latest version of Pega Robotic Automation that includes security patches for this vulnerability.
Who is affected by CVE-2026-1078?
CVE-2026-1078 affects users of Pega Robotic Automation version 22.1 or R25, specifically when running automations with Google Chrome or Microsoft Edge.
What are the potential impacts of CVE-2026-1078?
The impacts of CVE-2026-1078 can include unauthorized access to sensitive files and data manipulation, leading to data breaches.
Is CVE-2026-1078 actively being exploited?
As of now, there are no public reports indicating that CVE-2026-1078 is actively being exploited in the wild.