securityonline.info 22 Sept 2026, 01:42 UTC

Pega Warns of Critical SAML Flaws Affecting Platform Customers

Pega Warns of Critical SAML Flaws Affecting Platform Customers
CyberSIXT Evidence Panel Source marked as original reporting

PEGA disclosed two SAML authentication flaws in Pega Platform on 18 September 2026: one rated Critical with a CVSS score of 9.5 and another rated High at 7.0. The vendor tracks the issue internally as advisory P26; no CVE has been assigned. Pega said it is not aware of any compromises resulting from the vulnerabilities. The affected software range covers Pega Platform versions 8.1.x through 25.1.3, including on-premises and cloud deployments.

The weaknesses concern SAML response-signature validation. The platform previously accepted responses signed using the legacy RSAKeyValue method and, in some cases, unsigned assertions. An attacker could potentially exploit this behaviour to forge authentication responses and gain access without valid credentials. Pega’s fix removes this leniency: SAML responses must now be signed with an X.509 certificate, while unsigned responses and RSAKeyValue signatures are no longer supported.

Pega recommends upgrading to a fixed release, including version 26.1.1, released in September 2026, or the planned 25.1.4 release in October 2026. Customers on older supported versions should apply the relevant hotfixes and restart the server. Pega Cloud and Government Cloud customers receive hotfixes proactively; on-premises customers can obtain them through My Security Hotfixes on My Pega. Organisations should also work with their identity-provider teams to ensure SAML responses use only X.509 certificate signatures.

View full article

Article by CyberSIXT