Pega Customer Service Framework
cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*, +2 more
- >= 8, <= 25.1.0
A file upload vulnerability has been identified in Pega Customer Service Framework versions 8.7.0 prior to 25.1.0. This vulnerability allows privileged users to upload malicious files, potentially bypassing application-layer defenses.
Exploitation of this vulnerability could lead to unauthorized file uploads, allowing for the introduction of malicious files that could be used to compromise the application or its users.
Users can upgrade to Pega Customer Service versions 24.2.3 or 25.1.1. For version 26.1, the patch is targeted for Q2 2026.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.