Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ping Identity — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Ping Identity. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ping Identity operates as an enterprise identity and access management provider, specializing in single sign-on, multi-factor authentication, and API security for hybrid and cloud environments. Its software suite, which manages digital identities and permissions, has historically been associated with forty-eight recorded Common Vulnerabilities and Exposures. These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation or insecure direct object references within its web-based administrative interfaces. While the company has not been the subject of a widely publicized, large-scale data breach affecting millions of end-users, the high volume of CVEs indicates persistent challenges in securing its complex authentication infrastructure. These recurring issues highlight the risks inherent in deploying intricate identity governance tools, where misconfigurations or unpatched software components can potentially allow attackers to bypass authentication mechanisms or gain unauthorized administrative access to connected enterprise systems.

CVE ID Title CVSS Severity Published
CVE-2026-80327 Open Redirect in PingGateway Fragment Filter — PingGateway CWE-601 5.1 Medium 2026-10-06
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider — PingAM CWE-290 9.5 Critical 2026-09-14
CVE-2026-20773 Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint — PingFederate CWE-863 8.5 High 2026-09-14
CVE-2025-32736 PingFederate Administrative Console CSRF weaknesses — PingFederate CWE-352 4.9 Medium 2026-08-10
CVE-2026-20746 PingDirectory copying of virtual attributes leads to memory exhaustion — PingDirectory CWE-401 6.3 Medium 2026-06-12
CVE-2025-20628 Insufficient granularity of access control for Remote Connector Servers in client mode — PingIDM CWE-1220 5.9AI Medium AI 2026-04-07
CVE-2025-27935 Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit — One-Time Passcode Integration Kit for PingFederate CWE-306 7.5AI High AI 2025-12-04
CVE-2025-26862 PingFederate unexpected browser flow initiation in redirectless mode — PingFederate CWE-307 9.8AI Critical AI 2025-10-27
CVE-2024-25573 Stored Cross-Site Scripting in Administrative Console Context — PingFederate CWE-79 5.4AI Medium AI 2025-06-15
CVE-2025-22854 Possible thread exhaustion from processing http responses in PingFederate Google Adapter — PingFederate CWE-394 7.5AI High AI 2025-06-15
CVE-2025-21085 PingFederate OAuth Grant attribute duplication may use excessive memory — PingFederate CWE-462 7.5AI High AI 2025-06-15
CVE-2025-20059 PingAM Java Policy Agent path traversal — PingAM Java Policy Agent CWE-23 8.8 - 2025-02-20
CVE-2024-23983 Access rules for PingAccess may be circumvented with URL-encoded characters — PingAccess CWE-20 9.1AI Critical AI 2024-11-11
CVE-2024-25566 Open Redirect in PingAM — PingAM CWE-601 6.1AI Medium AI 2024-10-29
CVE-2024-23600 PingIDM Query Filter Vulnerability — PingIDM CWE-20 2.7 Low 2024-08-01
CVE-2024-21832 PingFederate REST API Data Store Injection — PingFederate CWE-94 3.5 Low 2024-07-09
CVE-2024-22377 PingFederate Runtime Node Path Traversal — PingFederate CWE-22 5.3 Medium 2024-07-09
CVE-2024-22477 PingFederate OIDC Policy Management Editor Cross-Site Scripting — PingFederate CWE-79 1.8 Low 2024-07-09
CVE-2023-40356 PingOne MFA Integration Kit MFA bypass — PingOne MFA Integration Kit for PingFederate CWE-290 5.3AI Medium AI 2024-07-09
CVE-2023-40702 PingOne MFA Integration Kit MFA bypass — PingOne MFA Integration Kit for PingFederate CWE-290 8.1AI High AI 2024-07-09
CVE-2024-23316 PingAccess HTTP Request Desynchronization Weakness — PingAccess CWE-444 7.5 - 2024-05-31
CVE-2023-40148 PingFederate Server Side Request Forgery vulnerability — PingFederate CWE-918 6.5 Medium 2024-04-10
CVE-2023-40545 PingFederate OAuth client_secret_jwt Authentication Bypass — PingFederate CWE-306 8.8 High 2024-02-06
CVE-2023-36496 Delegated Admin Virtual Attribute Provider Privilege Escalation — PingDirectory CWE-269 7.7 High 2024-02-01
CVE-2023-34085 User Attribute Disclosure via DynamoDB Data Stores — PingFederate CWE-359 2.6 Low 2023-10-25
CVE-2023-39219 Admin Console Denial of Service via Java class enumeration — PingFederate CWE-400 7.5 High 2023-10-25
CVE-2023-37283 Authentication Bypass via HTML Form & Identifier First Adapter — PingFederate CWE-287 8.1 High 2023-10-25
CVE-2023-39930 PingFederate PingID Radius PCV Authentication Bypass — PingID Radius PCV CWE-288 7.5 High 2023-10-24
CVE-2023-39231 PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass — PingOne MFA Integration Kit CWE-288 7.3 High 2023-10-24
CVE-2022-23721 PingID integration for Windows login duplicate username collision. — unspecified CWE-694 3.8 Low 2023-04-25

This page lists every published CVE security advisory associated with Ping Identity. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.