← Vulnerability feed

Vulnerability record · CVE-2021-27651 · published 29 April 2021

CVE-2021-27651: Pega Infinity password reset bypasses local authentication

Pega · Infinity

Pega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow can be abused to bypass local authentication checks, allowing an unauthenticated remote attacker to gain access to accounts. Because the affected component is internet-reachable in typical deployments and no credentials are required, this is a serious exposure for unpatched instances.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS percentile makes this an urgent patch for exposed Pega Infinity instances.

What it is

Pega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow can be abused to bypass local authentication checks, allowing an unauthenticated remote attacker to gain access to accounts. Because the affected component is internet-reachable in typical deployments and no credentials are required, this is a serious exposure for unpatched instances.

Impact

An attacker can bypass authentication and take over local accounts, gaining the access and privileges those accounts hold. With a CVSS base score of 9.8, the confidentiality, integrity and availability impact is rated high across the board.

Attack surface

Reached over the network through the password reset functionality for local accounts, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware use is documented. EPSS is high at roughly 0.54 probability (98.9th percentile), and the only references are vendor release notes and hotfix advisories, so no public exploit code is confirmed by this record.

What to do

  • Apply the Pega hotfix or upgrade past 8.5.2 per the vendor security advisory A21 hotfix matrix.
  • If patching cannot be done immediately, restrict network access to the Pega Infinity password reset endpoints to trusted sources.
  • Disable or tightly limit local account password reset where the business does not require it.
  • Monitor and alert on password reset requests followed by successful logins from the same source.
  • Audit local accounts for unexpected password changes or new sessions after the exposure window.

Detection

  • Alert on password reset requests for local accounts originating from unexpected IPs or user agents.
  • Correlate password reset events with immediate successful authentication from the same source.
  • Review Pega authentication and password reset logs for sequences that skip normal verification steps.
  • Hunt for anomalous logins to local accounts outside normal hours or geographies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27651 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-10094Pega infinity code injection vulnerabilityPega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of CodeEPSS 0.48%9.8CVE-2022-24083Pega infinity improper authorization vulnerabilityPassword authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.EPSS 0.91%9.8CVE-2022-24082Pega infinity deserialization of untrusted data vulnerabilityIf an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…EPSS 12%7.8CVE-2021-27654Pega infinity weak password recovery vulnerabilityForgotten password reset functionality for local accounts can be used to bypass local authentication checks.EPSS 0.60%4.9CVE-2021-27653Pega infinity improper access control vulnerabilityMisconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.EPSS 1.1%4.8CVE-2024-10716Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.EPSS 0.22%4.8CVE-2024-6702Pega infinity injection vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.EPSS 0.26%4.8CVE-2024-6700Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2021-27651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.