CVE-2026-0898

CRITICAL

Pega Browser Extension for Pega Robot Studio 22.1 and R25 - Arbitrary File Write

Title source: manual
STIX 2.1

Description

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The vulnerability may be exploited if a Pega Robot Studio developer is deceived into visiting this website during interrogation mode in Robot Studio.

Scores

CVSS v4 9.0
EPSS 0.0006
EPSS Percentile 18.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
Pegasystems/Pega Robot Studio 22.1
Pegasystems/Pega Robot Studio R25
Published Mar 23, 2026
Tracked Since Mar 24, 2026