CVE-2026-21391
9.5Ping Identity · PingAM
PingAM contains an improper validation flaw allowing attackers to override ID Token claims, potentially leading to authentication bypass, privilege escalation, or user impersonation.
Executive summary
A critical authentication bypass vulnerability in Ping Identity PingAM allows unauthenticated attackers to manipulate ID Token claims, posing a severe risk of unauthorized access and account takeover.
Vulnerability
This vulnerability involves improper validation of ID Token claims, classified under CWE-290 (Authentication bypass by spoofing). An unauthenticated attacker can supply crafted requests to modify protected claims, effectively bypassing authentication controls.
Business impact
The ability to spoof ID Token claims represents a complete compromise of the authentication and authorization integrity of the affected systems. Given the CVSS score of 9.5, this vulnerability is categorized as critical, as it enables attackers to escalate privileges or impersonate any user, leading to potential data exfiltration and total loss of confidentiality and integrity within the identity management environment.
Remediation
Immediate Action: Review the official Ping Identity security advisory at the provided link and apply the recommended updates or configuration changes to address the token validation flaw.
Proactive Monitoring: Review authentication and access logs for anomalous token requests or unexpected privilege elevation events that do not correlate with known user activity.
Compensating Controls: Implement strict Web Application Firewall (WAF) rules to inspect and filter incoming requests for suspicious or malformed ID Token parameters until patches are verified and applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and its direct impact on identity and access management, organizations must prioritize this issue as a top-tier security task. Administrators should verify their current version against the affected list immediately and coordinate with Ping Identity support to verify the appropriate mitigation path, as the provided fixed version data requires validation against the specific deployment architecture.
More Ping Identity CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section