CVE-2021-27651: Pega Infinity - Authentication Bypass

2025-08-01 Pega Infinity PoC Public

Description

Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.

PoC

id: CVE-2021-27651

info:
  name: Pega Infinity - Authentication Bypass
  author: idealphase,daffainfo
  severity: critical
  description: Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.
  impact: |
    Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Pega Infinity application.
  remediation: |
    Apply the necessary security patches or updates provided by Pega Infinity to mitigate the authentication bypass vulnerability (CVE-2021-27651).
  reference:
    - https://github.com/samwcyo/CVE-2021-27651-PoC/blob/main/RCE.md
    - https://nvd.nist.gov/vuln/detail/CVE-2021-27651
    - https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrix
    - https://github.com/nomi-sec/PoC-in-GitHub
    - https://github.com/orangmuda/CVE-2021-27651
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2021-27651
    cwe-id: CWE-287
    epss-score: 0.53841
    epss-percentile: 0.98944
    cpe: cpe:2.3:a:pega:infinity:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: pega
    product: infinity
  tags: cve2021,cve,pega,auth-bypass,passive,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/prweb/PRAuth/app/default/"

    host-redirects: true
    max-redirects: 2

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - compare_versions(version, '< 8.5.2', '>= 8.2.1')

      - type: word
        part: body
        words:
          - 'Pega Infinity'

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: version
        group: 1
        regex:
          - '(?m)<span>Pega ([0-9.]+)</span>'
        internal: true

      - type: regex
        group: 1
        regex:
          - '(?m)<span>Pega ([0-9.]+)</span>'
# digest: 490a00463044022074af8b4bc187065d0bdece34ed2c2558320b48c23e08aff1923f40902d24d74b02204c42443de23f8b4004f6cca592c5b4243a80bd95a644561f5b5237fe7b852ea4:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities