CVE-2026-1079 is a native messaging host vulnerability in Pega Browser Extension (PBE) that affects all versions of Pega Robotic Automation users who have installed the extension. An attacker could exploit this vulnerability by hosting malicious code on a website that, when visited by a user, triggers an unexpected message box through the compromised extension. The vulnerability requires user interaction in the form of website navigation, making it dependent on social engineering or user-directed visits to malicious sites. The FAUCET Risk Score of 43.0/100 indicates moderate risk, and exploitation activity appears minimal with an EPSS score of 0.00054, suggesting this vulnerability is not actively exploited in the wild. No exploit code is publicly available, and the vulnerability has not achieved significant community attention, as evidenced by its absence from the Known Exploited Vulnerabilities catalog and inactive status on security hotlists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Pegasystems | Pega Browser Extension (PBE) | >= 0, < 3.1.45CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.