← All Advisories

Pega Browser Extension arbitrary file write in Chrome and Edge automations via malicious website visit

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-1078

Key Details

CVECVE-2026-1078
CVSS Score / Version7.2 (High) / CVSS v4.0
Updated2026-06-17
Classified asCWE-284 (Improper Access Control)

What to Know

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime user navigates to the malicious website. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-1078
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-1078