---
id: CVE-2026-80327
title: >-
  An open redirect vulnerability exists in the PingGateway Fragment Filter
  feature
summary: >-
  An open redirect vulnerability exists in the PingGateway Fragment Filter
  feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0
  through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions
  2024.11.2, 202…
severity: medium
cvss: 5.1
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/S:P/AU:N/R:U/RE:M/U:Amber
cwe:
  - CWE-601
vendor: Ping Identity
product: PingGateway
affected:
  - PingGateway >= 7.1.0 <= 7.2.0
  - PingGateway >= 2023.2.0 <= 2024.11.1
  - PingGateway >= 2025.3.0 <= 2025.11.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T12:16:50.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80327'
references:
  - url: 'https://docs.pingidentity.com/pinggateway/release-notes/preface.html'
    label: responsible-disclosure@pingidentity.com
  - url: 'https://product-downloads.pingidentity.com/browse/ig/featured'
    label: responsible-disclosure@pingidentity.com
  - url: >-
      https://support.pingidentity.com/s/article/SECADV202602-Open-Redirect-in-PingGateway-Fragment-Filter
    label: responsible-disclosure@pingidentity.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T11:29:26.726005Z'
cvssSource: cna
ingestedAt: '2026-10-06T10:55:47.391Z'
---

## Overview

An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
