VYPR
Critical severity9.8NVD Advisory· Published Apr 29, 2021· Updated Jun 17, 2026

CVE-2021-27651

CVE-2021-27651

Description

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

Affected products

3
  • Pega/Infinityllm-create2 versions
    8.2.1 - 8.5.2+ 1 more
    • (no CPE)range: 8.2.1 - 8.5.2
    • cpe:2.3:a:pega:infinity:*:*:*:*:*:*:*:*range: >=8.2.1,<=8.5.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.