CVE-2026-0898
CRITICALPega Browser Extension for Pega Robot Studio 22.1 and R25 - Arbitrary File Write
Title source: manualDescription
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The vulnerability may be exploited if a Pega Robot Studio developer is deceived into visiting this website during interrogation mode in Robot Studio.
Scores
CVSS v4
9.0
EPSS
0.0006
EPSS Percentile
18.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (2)
Pegasystems/Pega Robot Studio
22.1
Pegasystems/Pega Robot Studio
R25
Published
Mar 23, 2026
Tracked Since
Mar 24, 2026