CVE-2026-14337: Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published Aug 4, 2026
·Updated
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Affected Software
1 affected component
Pega Pega Platform>=23.1.0<=25.1.3
Event History
Aug 4, 2026
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14337?
CVE-2026-14337 has a medium severity rating of 4.6 based on the CVSS score.
2
How do I fix CVE-2026-14337?
To remediate CVE-2026-14337, update the Pega Platform to a version beyond 25.1.3.
3
What systems are affected by CVE-2026-14337?
CVE-2026-14337 affects Pega Platform versions 23.1.0 through 25.1.3.
4
What type of vulnerability is CVE-2026-14337?
CVE-2026-14337 is identified as a Stored Cross-site Scripting (XSS) vulnerability.
5
Who needs to be concerned about CVE-2026-14337?
CVE-2026-14337 is a concern for high privileged users with a developer role in the Pega Platform.