CVE-2026-21391 PUBLISHED

Improper Claim Validation in PingAM OIDC Provider

Assigner: Ping Identity
Reserved: 07.01.2026 Published: 14.09.2026 Updated: 14.09.2026

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N
CVSS Score: 9.5

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Product Status

Vendor Ping Identity
Product PingAM
Versions Default: affected
  • Version 8.1.0 is affected
  • affected from 8.0.0 to 8.0.2 (incl.)
  • affected from 7.5.0 to 7.5.2 (incl.)
  • affected from 7.4.0 to 7.4.2 (incl.)
  • affected from 7.3.0 to 7.3.3 (incl.)
  • affected from 7.2.0 to 7.2.2 (incl.)
  • affected from 7.1.0 to 7.1.4 (incl.)
  • affected from 7.0.0 to 7.0.2 (incl.)
  • affected from 0 to 7.0.0 (excl.)

References

Problem Types

  • CWE-290 Authentication bypass by spoofing CWE

Impacts

  • CAPEC-21 Exploitation of Trusted Identifiers