TL;DR
Pega disclosed a Pega Platform SAML authentication bypass on September 18, 2026. It covers two flaws, one Critical (CVSS 9.5) and one High (CVSS 7.0). Pega has released patches and hotfixes. No compromise has been reported so far.
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Pega Platform SAML Bypass Matters
Pega Platform runs core workflows at many large enterprises, banks, and government agencies. SSO ties those apps to a single sign-on layer. A SAML authentication bypass breaks that trust boundary. As a result, an attacker could gain unauthorized access without valid credentials.
Pega classifies the root cause as Improper Authentication. The vendor states plainly: “To date, Pegasystems is not aware of any compromise resulting from these vulnerabilities; however, remediation should be implemented to maintain security.”
How the Attack Works
The weakness sits in how Pega validated SAML response signing. Previously, the platform accepted responses signed with legacy RSAKeyValue, and in some cases unsigned assertions. Attackers can abuse weak SAML signature validation to forge authentication responses. Pega’s fix removes that leniency at the mechanism level.
After patching, Pega enforces stricter rules. The advisory warns: “Pega no longer supports unsigned SAML responses or responses signed with RSAKeyValue.” Instead, identity providers must sign SAML responses with an X.509 certificate.
Affected Versions
The advisory lists affected Pega Platform versions from 8.1.x through 25.1.3. That range spans years of releases across on-premises and cloud deployments. No CVE was assigned to this Pega Platform SAML authentication bypass. Pega instead tracks it internally as advisory P26.
Patch and Mitigation Steps
Update to a fixed patch release, such as 26.1.1 (September 2026) or the planned 25.1.4 (October 2026). On older supported versions, apply the listed hotfixes, then restart the server. Pega Cloud and Government Cloud clients receive hotfixes proactively. On-premises clients should pull hotfixes from My Security Hotfixes on My Pega. Also coordinate with your IdP team to sign SAML responses using only an X.509 certificate.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!