Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.
id: CVE-2021-27651
info:
name: Pega Infinity - Authentication Bypass
author: idealphase,daffain
...