CVE-2026-20773 PUBLISHED

Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint

Assigner: Ping Identity
Reserved: 07.01.2026 Published: 14.09.2026 Updated: 14.09.2026

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
CVSS Score: 8.5

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Product Status

Vendor Ping Identity
Product PingFederate
Versions Default: unaffected
  • affected from 13.0.0 to 13.0.1 (incl.)
  • affected from 12.3.0 to 12.3.5 (incl.)
  • affected from 12.2.0 to 12.2.7 (incl.)
  • affected from 12.1.0 to 12.1.10 (incl.)
  • affected from 12.0.0 to 12.0.10 (incl.)
  • affected from 11.3.0 to 11.3.14 (incl.)

References

Problem Types

  • CWE-863: Incorrect Authorization CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs