CVE-2026-13761
Last modified
CVE-2026-13761 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Pegasystems | Pega Infinity | >= 7.1.0, < Infinity 25.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-13761?
How severe is CVE-2026-13761?
How do I fix CVE-2026-13761?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13756The WP Grid Builder plugin for WordPress is vulnerable to Pr…8.8
- CVE-2026-13757A flaw was found in p11-kit. The RPC message attribute parsi…6.2
- CVE-2026-13758CryptX versions before 0.088_001 for Perl compare AEAD authe…3.7
- CVE-2026-13759IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships th…8.8
- CVE-2026-1376IBM i 7.6 could allow a remote attacker to cause a denial of…7.5
- CVE-2026-13760OS command injection in the NodejsFunction Docker bundling p…7.3
- CVE-2026-13762Inconsistent interpretation of HTTP/2 requests in Amazon Clo…9.8
- CVE-2026-13763Inconsistent interpretation of HTTP/2 requests in AWS Applic…9.8
- CVE-2026-13765The LearnPress – WordPress LMS Plugin for Create and Sell On…7.5
- CVE-2026-13766DBIx::QuickORM versions before 0.000026 for Perl allow SQL i…9.8
- CVE-2026-13767The Quiz Master Next plugin for WordPress is vulnerable to S…6.5
- CVE-2026-13768Gardyn devices expose a privileged iothubowner key. Access t…10
Are you affected by CVE-2026-13761?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
