Executive Summary - Action Required
Pega regularly implements security controls designed to safeguard client environments. As part of these efforts, Pega will release patch updates and hotfixes addressing two vulnerabilities (one Critical and one High) identified in Pega Platform.
To date, Pegasystems is not aware of any compromise resulting from these vulnerabilities; however, remediation should be implemented to maintain security.
|
Advisory |
Description |
Patch Remediation |
Hotfix Remediation |
|---|---|---|---|
|
P26 |
SSO SAML Authentication Bypass
|
25.1.4 Patch Release (Target Oct 2026)
*26.1.0 Patch Release (Released July 2026)
26.1.1 Patch Release (Released Sept 2026) |
*26.1.0 - HFIX-D3036 25.1.3 - HFIX-D2231 25.1.2 - HFIX-D2561 24.2.5 - HFIX-D2232 24.2.4 - HFIX-D1709 24.1.4 - HFIX-D1710 23.1.5 - HFIX-D1761 8.8.5 - HFIX-D1762 8.7.6 - HFIX-D1763 8.6.6 - HFIX-D1764 8.5.6 - HFIX-D1765 8.4.6 - HFIX-D1766 8.3.6 - HFIX-D1767 8.2.8 - HFIX-D1768 8.1.9 - HFIX-D1769 |
*26.1.0 contains the appropriate fixes for the X509 certificate and removing RSAKeyValue support, however, it was not configured with the associated DSS setting as described by the Aug 3, 2026 Pulse post. The DSS setting is corrected by the hotfix HFIX-D3036 for 26.1.0.
Dates for upcoming patch releases can be found here: Pega Infinity Patch Calendar.
Information regarding the availability of the patch releases will be publicly posted on Pega Support Center September 18, 2026. We request that clients not discuss this in public forums until after this issue has been publicly posted to enable all customers to have adequate time to apply the necessary patches and/or hotfixes.
Impact
The SSO SAML authentication bypass patches and hotfixes address the risk of unauthorized access and enhance overall system security.
Issue Details
|
Issue Details |
Improper Authentication |
|---|---|
|
Software/Product |
Pega Platform |
|
Affected Version(s) |
From 8.1.x to 25.1.3 |
|
CVE |
No CVE |
|
CVSS Rating |
High - 7.0 & Critical - 9.5 |
|
Description |
SSO SAML Authentication Bypass |
As a best practice, you should update your Pega environment to the latest release to take advantage of the latest features, capabilities, security, and bug fixes. See Keeping Current with Pega for details.
Obtaining your Hotfixes
Hotfixes are being created only for the patch releases listed above, under Hotfix Remediation. A restart is needed after hotfix installation.
We will not provide hotfixes on prior versions of Pega Platform.
-
Pega Cloud® clients, using the versions listed above, will have hotfixes applied proactively, with Cloud Maintenance (CM) cases detailing the schedule. If you are not on a version with a solution provided, please update promptly.
-
United States Pega Cloud for Government (PCFG) clients will have Cloud Change (CC) cases created for relevant hotfixes, which Pega will apply. If you are not on a version with a solution provided, please update promptly.
-
On-premises or client-managed cloud clients should check the table above for applicable hotfixes and download them directly from My Security Hotfixes on My Pega.
Further examples of the new enforcement for SAML response signing
Below are the expected SAML login errors after the P26 SSO SAML Authentication Bypass fixes. They also identify the required remediation for each scenario.
Clients who still use legacy RSAKeyValue for SAML response signing may encounter login failures because Pega no longer supports legacy RSAKeyValue SAML response signing. Clients should use an X509 certificate to sign SAML messages instead.
Expected Error or Exception
After applying the hotfix or patch version, clients may encounter one of the following errors or exceptions:
Scenario 1:
Unable to process the SAML WebSSO request: Caught exception while validating SAML2 authentication response protocol. Public key signature is no longer supported. Please use an X509 certificate for signing SAML messages.
Reason for this exception
Pega no longer supports unsigned SAML responses or responses signed with RSAKeyValue.
We require IDPs to send SAML responses signed using an X509 certificate.
Recommended Action
Clients should work with their IdP team to ensure the SAML response is signed using only an X.509 certificate.
Using a combination of X.509 and RSAKeyValue will also cause SAML verification to fail.
Scenario 2:
When the IDP sends both Assertion and Response as unsigned, login fails with the following error message:
Unable to process the SAML WebSSO request: Caught Exception while validating SAML2 Authentication response protocol: Invalid SAML security. Expecting the SAML assertion to be signed
Recommended Action
Review the P26 Client Advisory (CAD) you received for the Recommended Action details for scenario 2
If you have questions or concerns, please raise a Support Ticket in My Support Portal.