CVE-2021-27651 describes a critical authentication bypass vulnerability in Pega Infinity versions 8.2.1 through 8.5.2, allowing attackers to circumvent local authentication via the password reset functionality. With a CVSS score of 9.8 (Critical), this vulnerability is remotely exploitable with low complexity, enabling full compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Nuclei template exists for detection, and its high EPSS and FAUCET scores indicate a significant likelihood of exploitation despite no observed active exploitation or public discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.2.1, <= 8.5.2CPE matchmatch criteria | cpe:2.3:a:pega:infinity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.