CVE-2025-62181Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication feature and other more secure authentication mechanisms are recommended. A fix is being provided in the 24.1.4, 24.2.4, and 25.1.1 patch releases. Please note: Basic credentials authentication service type is deprecated started in 24.2 version: https://docs.pega.com/bundle/platform/page/platform/release-notes/security/whats-new-security-242.html.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-19: 1Technical Details · 2026-03-19: 103-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Autumn Good@autumn_good_35
    Disclosure

    1) Weak Brute-Force protection for login page (CVE-2025-62181) 2) Insecure Direct Object Reference (IDOR) (CVE-2025-9559) Multiple vulnerabilities in PEGA Infinity platform - SEC Consult https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-pega-infinity-platform/

    Post summary

    The advisory announces CVE‑2025‑62181 (weak brute‑force protection) and CVE‑2025‑9559 (IDOR) in the PEGA Infinity platform, with no PoC, exploit, or patch details disclosed.

    00000411
    6.7K followersView on X

Explore more