Denial of Service in Ping Identity PingDirectory Due to Virtual Attribute Mismanagement
CVE-2026-20746
6.3MEDIUM
What is CVE-2026-20746?
A vulnerability in Ping Identity's PingDirectory allows authorized users to cause a denial of service by exhausting the Java memory heap. This issue occurs when recent login history is enabled and users attempt to copy virtual attributes that reference ds-privilege-name values. Exploiting this vulnerability can lead to service interruptions, impacting the overall system performance and availability.
Affected Version(s)
PingDirectory 9.3.0.0 <= 9.3.0.8
PingDirectory 10.2.0.0 <= 10.2.0.5
PingDirectory 10.3.0.0 <= 10.3.0.3
