Ping Identity has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.0 (critical), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2026-21391Critical· 9.5An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden52CVE-2026-20773High· 8.5A role-based access control issue was identified in the administrative expression evaluation functionality47
Ping Identity vulnerabilities
CVEs affecting Ping Identity, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-20773High· 8.5A role-based access control issue was identified in the administrative expression evaluation functionality
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissi…
CVE-2026-21391Critical· 9.5An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication…