{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-21391","assignerOrgId":"5998a2e9-ae88-42cd-b6e0-7564fd979f9e","state":"PUBLISHED","assignerShortName":"Ping Identity","dateReserved":"2026-01-07T15:15:23.421Z","datePublished":"2026-09-14T11:18:33.045Z","dateUpdated":"2026-09-14T14:25:10.479Z"},"containers":{"cna":{"providerMetadata":{"orgId":"5998a2e9-ae88-42cd-b6e0-7564fd979f9e","shortName":"Ping Identity","dateUpdated":"2026-09-14T11:18:33.045Z"},"title":"Improper Claim Validation in PingAM OIDC Provider","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-290","description":"CWE-290 Authentication bypass by spoofing","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-21","descriptions":[{"lang":"en","value":"CAPEC-21 Exploitation of Trusted Identifiers"}]}],"affected":[{"vendor":"Ping Identity","product":"PingAM","versions":[{"status":"affected","version":"8.1.0","versionType":"semver"},{"status":"affected","version":"8.0.0","lessThanOrEqual":"8.0.2","versionType":"semver"},{"status":"affected","version":"7.5.0","lessThanOrEqual":"7.5.2","versionType":"semver"},{"status":"affected","version":"7.4.0","lessThanOrEqual":"7.4.2","versionType":"semver"},{"status":"affected","version":"7.3.0","lessThanOrEqual":"7.3.3","versionType":"semver"},{"status":"affected","version":"7.2.0","lessThanOrEqual":"7.2.2","versionType":"semver"},{"status":"affected","version":"7.1.0","lessThanOrEqual":"7.1.4","versionType":"semver"},{"status":"affected","version":"7.0.0","lessThanOrEqual":"7.0.2","versionType":"semver"},{"status":"affected","version":"0","lessThan":"7.0.0","changes":[{"at":"0","status":"affected"}],"versionType":"semver"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div>An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.</div><br>"}]}],"references":[{"url":"https://support.pingidentity.com/s/article/PingAM-Security-Advisory-202603"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.5,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N"}}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-14T14:24:57.614272Z","id":"CVE-2026-21391","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T14:25:10.479Z"}}]}}