CVE-2026-20773

Summary

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

Affected Software

VendorProductVersion RangeStatus
Ping IdentityPingFederate13.0.0 <= 13.0.1affected
Ping IdentityPingFederate12.3.0 <= 12.3.5affected
Ping IdentityPingFederate12.2.0 <= 12.2.7affected
Ping IdentityPingFederate12.1.0 <= 12.1.10affected
Ping IdentityPingFederate12.0.0 <= 12.0.10affected
Ping IdentityPingFederate11.3.0 <= 11.3.14affected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References