CVE-2026-21391

9.5

Ping Identity · PingAM

PingAM contains an improper validation flaw allowing attackers to override ID Token claims, potentially leading to authentication bypass, privilege escalation, or user impersonation.

Executive summary

A critical authentication bypass vulnerability in Ping Identity PingAM allows unauthenticated attackers to manipulate ID Token claims, posing a severe risk of unauthorized access and account takeover.

Vulnerability

This vulnerability involves improper validation of ID Token claims, classified under CWE-290 (Authentication bypass by spoofing). An unauthenticated attacker can supply crafted requests to modify protected claims, effectively bypassing authentication controls.

Business impact

The ability to spoof ID Token claims represents a complete compromise of the authentication and authorization integrity of the affected systems. Given the CVSS score of 9.5, this vulnerability is categorized as critical, as it enables attackers to escalate privileges or impersonate any user, leading to potential data exfiltration and total loss of confidentiality and integrity within the identity management environment.

Remediation

Immediate Action: Review the official Ping Identity security advisory at the provided link and apply the recommended updates or configuration changes to address the token validation flaw.

Proactive Monitoring: Review authentication and access logs for anomalous token requests or unexpected privilege elevation events that do not correlate with known user activity.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to inspect and filter incoming requests for suspicious or malformed ID Token parameters until patches are verified and applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and its direct impact on identity and access management, organizations must prioritize this issue as a top-tier security task. Administrators should verify their current version against the affected list immediately and coordinate with Ping Identity support to verify the appropriate mitigation path, as the provided fixed version data requires validation against the specific deployment architecture.

More Ping Identity CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources