{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-62180", "assignerOrgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "state": "PUBLISHED", "assignerShortName": "Pega", "dateReserved": "2025-10-07T19:04:27.220Z", "datePublished": "2026-06-23T14:48:36.267Z", "dateUpdated": "2026-06-23T17:03:35.508Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "shortName": "Pega", "dateUpdated": "2026-06-23T14:48:36.267Z" }, "title": "Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.", "datePublic": "2026-06-22T15:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-639", "description": "CWE-639: Authorization Bypass Through User-Controlled Key", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-180", "descriptions": [ { "lang": "en", "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels" } ] } ], "affected": [ { "vendor": "Pegasystems", "product": "Pega Infinity", "versions": [ { "status": "affected", "version": "8.3.0", "lessThan": "Infinity 25.1.3", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "