Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-20773 1 Ping Identity 1 Pingfederate 2026-09-14 N/A
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
CVE-2025-32736 1 Ping Identity 1 Pingfederate 2026-08-28 N/A
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.
CVE-2026-20746 2 Ping Identity, Pingidentity 2 Pingdirectory, Pingdirectory 2026-08-28 N/A
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.