CVE-2026-20773
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Summary
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ping Identity | PingFederate | 13.0.0 <= 13.0.1 | affected |
| Ping Identity | PingFederate | 12.3.0 <= 12.3.5 | affected |
| Ping Identity | PingFederate | 12.2.0 <= 12.2.7 | affected |
| Ping Identity | PingFederate | 12.1.0 <= 12.1.10 | affected |
| Ping Identity | PingFederate | 12.0.0 <= 12.0.10 | affected |
| Ping Identity | PingFederate | 11.3.0 <= 11.3.14 | affected |
Weaknesses
- CWE-863: CWE-863: Incorrect Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.