CVE-2026-20773
Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
| CWE | CWE-863 |
| Vendor | ping identity |
| Product | pingfederate |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for ping identity pingfederate
Be the first to know when new unknown vulnerabilities affecting ping identity pingfederate are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Ping Identity / PingFederate
13.0.0 ≤ 13.0.1 12.3.0 ≤ 12.3.5 12.2.0 ≤ 12.2.7 12.1.0 ≤ 12.1.10 12.0.0 ≤ 12.0.10 11.3.0 ≤ 11.3.14