CVE-2026-1563: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Published Jul 15, 2026
·Updated
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Affected Software
3 affected components
Pega Pega Platform>=8.1.0<=25.1.2
Pega Pega Platform>=8.1<24.2.4
Pega Pega Platform>=25.1.0<25.1.3
Event History
Jul 15, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1563?
The severity of CVE-2026-1563 is medium with a CVSS score of 4.8.
2
What versions of Pega Platform are affected by CVE-2026-1563?
Pega Platform versions 8.1.0 through 25.1.2 are affected by CVE-2026-1563.
3
How do I fix CVE-2026-1563?
To fix CVE-2026-1563, update to a version of Pega Platform that is not affected by this vulnerability.
4
Who is at risk from CVE-2026-1563?
Users with a high privileged developer role are at risk from CVE-2026-1563.
5
What type of vulnerability is CVE-2026-1563?
CVE-2026-1563 is a Reflected Cross-site Scripting (XSS) vulnerability.