← Vulnerability feed

Vulnerability record · CVE-2021-27653 · published 1 April 2021

CVE-2021-27653: Pega infinity improper access control vulnerability

Pega · Infinity

Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

4.9 CVSS 3.1 Medium EPSS 1.1% · top 36.1% CWE-284 · Improper access control
4.9CVSS 3.1 base score, v2 4.0
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27653 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-10094Pega infinity code injection vulnerabilityPega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of CodeEPSS 0.48%9.8CVE-2022-24083Pega infinity improper authorization vulnerabilityPassword authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.EPSS 0.91%9.8CVE-2022-24082Pega infinity deserialization of untrusted data vulnerabilityIf an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…EPSS 12%9.8CVE-2021-27651Pega Infinity password reset bypasses local authenticationPega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow …EPSS 54%analysed7.8CVE-2021-27654Pega infinity weak password recovery vulnerabilityForgotten password reset functionality for local accounts can be used to bypass local authentication checks.EPSS 0.60%4.8CVE-2024-10716Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.EPSS 0.22%4.8CVE-2024-6702Pega infinity injection vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.EPSS 0.26%4.8CVE-2024-6700Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2021-27653), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.