CVE-2026-80327 PUBLISHED

Open Redirect in PingGateway Fragment Filter

Assigner: Ping Identity
Reserved: 26.08.2026 Published: 06.10.2026 Updated: 06.10.2026

An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/S:P/AU:N/R:U/RE:M/U:Amber
CVSS Score: 5.1

Product Status

Vendor Ping Identity
Product PingGateway
Versions Default: unaffected
  • affected from 7.1.0 to 7.2.0 (incl.)
  • affected from 2023.2.0 to 2024.11.1 (incl.)
  • affected from 2025.3.0 to 2025.11.1 (incl.)

References

Problem Types

  • CWE-601 URL redirection to untrusted site ('open redirect') CWE