🔐 CVE Alert

CVE-2026-20773

UNKNOWN 0.0

Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

CWE CWE-863
Vendor ping identity
Product pingfederate
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for ping identity pingfederate

Be the first to know when new unknown vulnerabilities affecting ping identity pingfederate are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Ping Identity / PingFederate
13.0.0 ≤ 13.0.1 12.3.0 ≤ 12.3.5 12.2.0 ≤ 12.2.7 12.1.0 ≤ 12.1.10 12.0.0 ≤ 12.0.10 11.3.0 ≤ 11.3.14

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.pingidentity.com: https://support.pingidentity.com/s/article/SECADV054-Improper-Authorization-in-PingFederate-Administrative-Expression-Evaluation-Endpoint