Improper Validation in PingIdentity Product
CVE-2026-21391
9.5CRITICAL
What is CVE-2026-21391?
An improper validation vulnerability present in PingAccess Management allows attackers to craft requests that can set or alter arbitrary or protected ID Token claims. This could lead to bypassing authentication controls and potential scenarios of privilege escalation or impersonation, particularly in specific configurations. Organizations using this product should review their configurations and apply necessary updates to mitigate risks.
Affected Version(s)
PingAM 8.1.0
PingAM 8.1.0
PingAM 8.0.0 <= 8.0.2
