CVE-2026-1562: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published Jul 15, 2026
·Updated
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Affected Software
3 affected components
Pega Pega Platform>=8.1.0<=25.1.2
Pega Pega Platform>=8.1<24.2.4
Pega Pega Platform>=25.1.0<25.1.3
Event History
Jul 15, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1562?
CVE-2026-1562 has a medium severity rating of 4.6 according to the CVSS scoring system.
2
What is the nature of the vulnerability in CVE-2026-1562?
CVE-2026-1562 is a Stored Cross-site Scripting (XSS) vulnerability affecting a user interface component.
3
Who is impacted by CVE-2026-1562?
CVE-2026-1562 impacts high privileged users with a developer role using Pega Platform versions 8.1.0 through 25.1.2.
4
How do I fix CVE-2026-1562?
To remediate CVE-2026-1562, ensure that you update to a patched version of Pega Platform beyond 25.1.2.
5
What versions of Pega Platform are affected by CVE-2026-1562?
CVE-2026-1562 affects Pega Platform versions from 8.1.0 through 25.1.2.