CVE-2026-1079
A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension.
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website. The malicious website could then present an unexpected message box.
| CWE | CWE-284 |
| Vendor | pegasystems |
| Product | pega browser extension (pbe) |
| Published | Apr 7, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for pegasystems pega browser extension (pbe)
Be the first to know when new unknown vulnerabilities affecting pegasystems pega browser extension (pbe) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Pegasystems / Pega Browser Extension (PBE)
0 < 3.1.45
References
Credits
Ramon Dunker from Achmea, Security Assessment Team