← Back to browse · API

CVE-2021-27651

Severity
CRITICAL
CVSS
9.8
EPSS
0.53841
Risk score
58.04
CISA KEV
No
PoC
No
Published
2021-04-29
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-14397, GHSA-7PX5-VQMH-8XJ8
Products
Pegasystems:Pega Infinity 8.2.1 <unspecified, Pegasystems:Pega Infinity unspecified <8.5.2
Sources
euvd EUVD-2021-14397

Description

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

References