Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pegasystems
Pegasystems pega Robot Studio |
|
| Vendors & Products |
Pegasystems
Pegasystems pega Robot Studio |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime user navigates to the malicious website. | |
| Title | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Pega
Published:
Updated: 2026-04-07T19:59:49.928Z
Reserved: 2026-01-16T20:29:54.621Z
Link: CVE-2026-1078
Updated: 2026-04-07T19:55:42.609Z
Status : Awaiting Analysis
Published: 2026-04-07T16:16:23.200
Modified: 2026-04-08T21:27:00.663
Link: CVE-2026-1078
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:48:30Z