CVE-2026-1079: A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension.
A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website. The malicious website could then present an unexpected message box.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1079?
CVE-2026-1079 is classified as a critical vulnerability affecting the Pega Browser Extension.
How do I fix CVE-2026-1079?
To mitigate CVE-2026-1079, users should update to the latest version of the Pega Browser Extension provided by Pegasystems.
Who is affected by CVE-2026-1079?
All users of Pega Robotic Automation with the Pega Browser Extension installed are affected by CVE-2026-1079.
What types of attacks can exploit CVE-2026-1079?
CVE-2026-1079 may allow an attacker to execute arbitrary code through the native messaging host.
Is there a workaround for CVE-2026-1079?
Currently, the only recommended action for CVE-2026-1079 is to apply the security update provided by Pegasystems.