Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pegasystems
Pegasystems pega Browser Extension (pbe) |
|
| Vendors & Products |
Pegasystems
Pegasystems pega Browser Extension (pbe) |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website. The malicious website could then present an unexpected message box. | |
| Title | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Pega
Published:
Updated: 2026-04-07T20:06:55.833Z
Reserved: 2026-01-16T20:29:58.229Z
Link: CVE-2026-1079
Updated: 2026-04-07T20:06:53.274Z
Status : Awaiting Analysis
Published: 2026-04-07T16:16:23.370
Modified: 2026-04-08T21:27:00.663
Link: CVE-2026-1079
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:48:22Z