CVE-2026-1078 is an arbitrary file-write vulnerability in the Pega Browser Extension affecting Pega Robotic Automation versions 22.1 and R25 users on Google Chrome and Microsoft Edge browsers. An attacker could exploit this by hosting malicious code on a website that, if visited by a Robot Runtime user, would enable unauthorized file writing on the affected system. The vulnerability represents a moderate security concern with a FAUCET Risk Score of 37.0/100, though formal CVSS metrics are not yet available. The attack requires user interaction (visiting a malicious website) and is limited to users actively running automations, reducing the overall threat surface. Currently, this vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild, with minimal community attention based on inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Pegasystems | Pega Robot Studio | 22.1, R25CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.