Executive Summary - Action Required
Pega regularly implements security controls designed to safeguard client environments. As part of these efforts, Pega will release patch updates and hotfixes addressing one medium-severity security vulnerability in Pega Platform. This issue can only be exploited by users with Pega Developer/Admin access.
To date, Pega is not aware of any compromise resulting from this vulnerability; however, remediation should be implemented to maintain security.
We would like to thank Andrea Intilangelo, independent ethical hacker/security researcher for finding and responsibly disclosing this vulnerability.
|
Advisory |
Description |
Patch Remediation |
Hotfix Remediation |
|---|---|---|---|
|
O26 |
Cross-Site Scripting (XSS) vulnerability (App Studio) |
24.1.5 Patch Release (Targeted Aug ’26) 25.1.4 Patch Release (Targeted Oct. ‘26) 26.1.1 Patch Release (Targeted Aug ‘26) |
25.1.3 - HFIX-D1620 24.2.5 - HFIX-D2061 *26.1 (TBC.) |
*Hotfixes for 26.1 will be issued at a later date.
Dates for upcoming patch releases can be found here: Pega Infinity Patch Calendar.
Information regarding the availability of the patch releases will be publicly posted on Pega Support Center August 4, 2026. We request that clients not discuss this in public forums until after this issue has been publicly posted to enable all clients to have adequate time to apply the necessary patches and/or hotfixes.
Impact
Cross-site scripting (XSS) is an attack in which an attacker injects malicious executable scripts into the code of a trusted application or website. Attackers often initiate an XSS attack by sending a malicious link to a user and enticing the user to click it.
Issue Details
|
Issue Details |
Cross-Site Scripting (XSS) |
|---|---|
|
Software/Product |
Pega Platform |
|
Affected Version(s) |
From 23.1 to 25.1.3 |
|
CVE |
CVE-2026-14337 |
|
CVSS Rating |
Medium – 4.6 |
|
Description |
Cross-Site Scripting (XSS) |
As a best practice, you should update your Pega environment to the latest release to take advantage of the latest features, capabilities, security, and bug fixes. See Keeping Current with Pega for details.
Obtaining your Hotfixes
Hotfixes are being created only for the patch releases listed above, under Hotfix Remediation. A restart is NOT needed after hotfix installation.
We will not provide hotfixes on prior versions of Pega Platform.
- Pega Cloud® and Pega Cloud for Government (PCFG) clients, using the versions listed above, will have hotfixes applied proactively, with Cloud Maintenance (CM) cases detailing the schedule. If you are not on a version with a solution provided, please update promptly.
- On-premises or client-managed cloud clients should check the table above for applicable hotfixes and download them directly from My Security Hotfixes on My Pega.
If you have questions or concerns, please raise a Support Ticket in My Support Portal.