{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-14337", "assignerOrgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "state": "PUBLISHED", "assignerShortName": "Pega", "dateReserved": "2026-07-01T13:14:37.060Z", "datePublished": "2026-08-04T13:48:40.493Z", "dateUpdated": "2026-08-04T18:00:09.856Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "shortName": "Pega", "dateUpdated": "2026-08-04T13:48:40.493Z" }, "title": "Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.", "datePublic": "2026-08-04T20:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-79", "description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-592", "descriptions": [ { "lang": "en", "value": "CAPEC-592: Stored XSS" } ] } ], "affected": [ { "vendor": "Pegasystems", "product": "Pega Infinity", "versions": [ { "status": "affected", "version": "23.1.0", "lessThan": "Infinity 25.1.4", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "