CVE-2026-80327
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/S:P/AU:N/R:U/RE:M/U:Amber
Summary
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ping Identity | PingGateway | 7.1.0 <= 7.2.0 | affected |
| Ping Identity | PingGateway | 2023.2.0 <= 2024.11.1 | affected |
| Ping Identity | PingGateway | 2025.3.0 <= 2025.11.1 | affected |
Weaknesses
- CWE-601: CWE-601 URL redirection to untrusted site ('open redirect')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://docs.pingidentity.com/pinggateway/release-notes/preface.html
- https://product-downloads.pingidentity.com/browse/ig/featured
- https://support.pingidentity.com/s/article/SECADV202602-Open-Redirect-in-PingGateway-Fragment-Filter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.