Identity and access management

Ping Identity advisories: every record the registers tie to its products

In one line

24 advisories are attributed to Ping Identity products in this record, covering September 2022 to June 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 3 register entries mention Ping Identity without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

24

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

1

by the register

Last checked

Jul 27, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Ping Identity, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

3 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

23 of the 24 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-20746mediumCVSS 6.3Jun 12, 2026

    Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying…

  • CVE-2025-20628mediumCVSS 6.9Apr 07, 2026

    An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote…

  • CVE-2025-27935highCVSS 8.6Dec 04, 2025

    The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly.

  • CVE-2025-26862Oct 27, 2025

    Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login…

  • CVE-2024-25573mediumCVSS 6.9Jun 15, 2025

    Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

  • CVE-2025-22854mediumCVSS 6.9Jun 15, 2025

    Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

  • CVE-2025-21085lowCVSS 2.1Jun 15, 2025

    PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

  • CVE-2025-20059criticalCVSS 9.2Feb 20, 2025

    Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1…

  • CVE-2024-23983mediumCVSS 5.8Nov 11, 2024

    Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

  • CVE-2024-25566mediumCVSS 5.1Oct 29, 2024

    An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs.

  • CVE-2024-23600lowCVSS 2.7Aug 01, 2024

    Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information…

  • CVE-2023-40148mediumCVSS 6.5Apr 10, 2024

    Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.

  • CVE-2023-40545highCVSS 8.8Feb 06, 2024

    Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

  • CVE-2023-36496highCVSS 7.7Feb 01, 2024

    Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

  • CVE-2023-34085lowCVSS 2.6Oct 25, 2023

    When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

  • CVE-2023-39219highCVSS 7.5Oct 25, 2023

    PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

  • CVE-2023-39930highCVSS 7.5Oct 24, 2023

    A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client…

  • CVE-2023-39231highCVSS 7.3Oct 24, 2023

    PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device.

  • CVE-2022-40724mediumCVSS 6.4Apr 25, 2023

    The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.

  • CVE-2022-40725highCVSS 7.3Apr 25, 2023

    PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is…

  • CVE-2022-40722highCVSS 7.7Apr 25, 2023

    A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary…

  • CVE-2022-23721lowCVSS 3.8Apr 25, 2023

    PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the…

  • CVE-2022-40723mediumCVSS 6.5Apr 25, 2023

    The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

  • CVE-2022-23726mediumCVSS 5.4Sep 30, 2022

    PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application…

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union26Jun 12, 2026
National Vulnerability DatabaseNIST, United States Department of Commerce2Jun 12, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany1Mar 27, 2023

The entry counts here are the raw register totals for Ping Identity, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Ping Identity have?

24 advisories in this record are tied by a register to a product of Ping Identity. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Ping Identity vulnerabilities being actively exploited?

None of the 24 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Ping Identity than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 3 register entries name Ping Identity without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Ping Identity advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); National Vulnerability Database (NIST, United States Department of Commerce); CERT-Bund security advisories (BSI, Federal Republic of Germany). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Ping Identity is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Ping Identity record, including sources and open questions

Ping Identity vulnerabilities: all 24 advisories on record, with sources | DecisionOS by nexalign