Vulnerabilities > Pega > Synchronization Engine

DATE CVE VULNERABILITY TITLE RISK
2023-04-10 CVE-2023-26467 Insufficient Verification of Data Authenticity vulnerability in Pega Synchronization Engine
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
network
high complexity
pega CWE-345
5.4
2023-04-10 CVE-2023-26466 Unspecified vulnerability in Pega Synchronization Engine
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
local
low complexity
pega
7.8
2023-04-10 CVE-2023-28093 Improper Certificate Validation vulnerability in Pega Synchronization Engine
A user with a compromised configuration can start an unsigned binary as a service.
network
low complexity
pega CWE-295
6.5