Vulnerability record · CVE-2021-27651 · published 29 April 2021
CVE-2021-27651: Pega Infinity password reset bypasses local authentication
Pega · Infinity
Pega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow can be abused to bypass local authentication checks, allowing an unauthenticated remote attacker to gain access to accounts. Because the affected component is internet-reachable in typical deployments and no credentials are required, this is a serious exposure for unpatched instances.
Description
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS percentile makes this an urgent patch for exposed Pega Infinity instances.
What it is
Pega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow can be abused to bypass local authentication checks, allowing an unauthenticated remote attacker to gain access to accounts. Because the affected component is internet-reachable in typical deployments and no credentials are required, this is a serious exposure for unpatched instances.
Impact
An attacker can bypass authentication and take over local accounts, gaining the access and privileges those accounts hold. With a CVSS base score of 9.8, the confidentiality, integrity and availability impact is rated high across the board.
Attack surface
Reached over the network through the password reset functionality for local accounts, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high at roughly 0.54 probability (98.9th percentile), and the only references are vendor release notes and hotfix advisories, so no public exploit code is confirmed by this record.
What to do
- Apply the Pega hotfix or upgrade past 8.5.2 per the vendor security advisory A21 hotfix matrix.
- If patching cannot be done immediately, restrict network access to the Pega Infinity password reset endpoints to trusted sources.
- Disable or tightly limit local account password reset where the business does not require it.
- Monitor and alert on password reset requests followed by successful logins from the same source.
- Audit local accounts for unexpected password changes or new sessions after the exposure window.
Detection
- Alert on password reset requests for local accounts originating from unexpected IPs or user agents.
- Correlate password reset events with immediate successful authentication from the same source.
- Review Pega authentication and password reset logs for sequences that skip normal verification steps.
- Hunt for anomalous logins to local accounts outside normal hours or geographies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrix | Release NotesVendor Advisory |
| https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrix | Release NotesVendor Advisory |
Track CVE-2021-27651 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.