securityonline.info
Pega Platform SAML Authentication Bypass: Critical 9.5 Flaw Patched
TL;DR Pega disclosed a Pega Platform SAML authentication bypass on September 18, 2026. It covers two flaws, one Critical (CVSS 9.5) and one High (CVSS 7.0). Pega has released patches and hotfixes. No compromise has been reported so far. Why This Pega Platform SAML Bypass Matters Pega Platform runs core workflows at many large enterprises, banks, and government agencies. SSO ties those apps to a single sign-on layer.