CVE-2026-13761
largeUnauthenticated excessive-looping DoS in Pega Platform 7.1.0-25.1.2
Pega Platform versions 7.1.0 through 25.1.2 fail to properly validate inputs that are used as loop conditions, allowing crafted input to drive excessive or effectively unbounded looping. The flaw is reachable over the network without authentication or user interaction, per the CVSS 4.0 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker can consume processing resources and cause a denial of service, and the vector's high integrity impact suggests the vendor's 'other consequences' may extend beyond pure availability, though confidentiality is not impacted. Any organization running Pega Platform within the affected version range is exposed, whether deployed on-premises, in private cloud, or as the back end for internet-facing applications. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days, so exploitation has not yet been observed.
What to do: Inventory all Pega Platform deployments and check their versions against the affected range of 7.1.0 through 25.1.2, then upgrade to a release later than 25.1.2 as specified in Pega's security bulletin (confirm the exact fixed version with the vendor advisory, as it is not stated in this data). Until patching, restrict network access to Pega servers, particularly any internet-facing instances, and monitor for abnormal CPU consumption or hung processes. Watch Pega's advisories and the CISA KEV catalog, since the unauthenticated network vector could make this attractive once exploitation details emerge.
| Pegasystems (Pega) Pega Platform | 7.1.0 through 25.1.2 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
- Weakness
- CWE-606
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.