CVE-2026-21391

Summary

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

Affected Software

VendorProductVersion RangeStatus
Ping IdentityPingAM8.1.0affected
Ping IdentityPingAM8.0.0 <= 8.0.2affected
Ping IdentityPingAM7.5.0 <= 7.5.2affected
Ping IdentityPingAM7.4.0 <= 7.4.2affected
Ping IdentityPingAM7.3.0 <= 7.3.3affected
Ping IdentityPingAM7.2.0 <= 7.2.2affected
Ping IdentityPingAM7.1.0 <= 7.1.4affected
Ping IdentityPingAM7.0.0 <= 7.0.2affected
Ping IdentityPingAM0 < 7.0.0affected

Weaknesses

  • CWE-290: CWE-290 Authentication bypass by spoofing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References