CVE-2026-1711: Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1711?
The severity of CVE-2026-1711 is classified as high due to the potential impact of stored cross-site scripting attacks.
How do I fix CVE-2026-1711?
To fix CVE-2026-1711, update the Pega Platform to version 25.1.2 or higher.
Who is affected by CVE-2026-1711?
CVE-2026-1711 affects high privileged users with developer roles on Pega Platform versions 8.1.0 through 25.1.1.
What types of attacks are possible with CVE-2026-1711?
CVE-2026-1711 allows attackers to execute arbitrary JavaScript in the context of the user’s session, leading to potential data theft or manipulation.
Is CVE-2026-1711 still a risk if I upgrade my software regularly?
Even with regular upgrades, if the Pega Platform is not updated to version 25.1.2 or higher, CVE-2026-1711 remains a risk.