AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14337

MEDIUM · CVSS 4.6 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Pega Platform versions 23.1.0 through 25.1.3, specifically within a user interface component that is susceptible to stored cross-site scripting (XSS) attacks. This issue requires a high-privileged user with a developer role to exploit, potentially allowing attackers to execute malicious scripts in the context of other users. Organizations using these versions of the Pega Platform, particularly those with elevated user roles, should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-14337
Severity
MEDIUM
CVSS
4.6
EPSS
0.25%

Original NVD Description

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.