CVE-2026-80327

Summary

An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).

Affected Software

VendorProductVersion RangeStatus
Ping IdentityPingGateway7.1.0 <= 7.2.0affected
Ping IdentityPingGateway2023.2.0 <= 2024.11.1affected
Ping IdentityPingGateway2025.3.0 <= 2025.11.1affected

Weaknesses

  • CWE-601: CWE-601 URL redirection to untrusted site ('open redirect')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References