PT-2026-27174 · Pega · Pega Browser Extension

Ramon Dunker

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-0898

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Pega Browser Extension versions 22.1 and R25
Description A flaw exists in Pega Browser Extension that could allow a malicious actor to create a website containing harmful code. This issue impacts Pega Robot Studio developers automating Google Chrome and Microsoft Edge during interrogation mode. Exploitation requires deceiving a developer into visiting a compromised website. The vulnerability does not affect Robot Runtime users.
Recommendations Update Pega Browser Extension to a newer version that addresses this issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-0898

Affected Products

Pega Browser Extension