ZeroHour

CVE-2026-20773

moderate1

Role-Based Access Control Flaw in Ping Identity Admin Expression Evaluation

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20773 is a role-based access control flaw (CWE-863) in the administrative expression evaluation functionality of a Ping Identity product, disclosed via Ping Identity's responsible disclosure program. A user holding one of certain administrative roles can trigger the issue by invoking the expression testing capability through the administrative interface, which should only be accessible to higher-privileged administrators. Successful abuse lets the attacker test and evaluate expressions beyond their intended permissions, and the high CVSS 4.0 score (8.5) with high subsequent-system, integrity, and availability impacts indicates the capability could be leveraged to affect downstream systems and data. Organizations running the affected Ping Identity deployment — particularly those with multiple administrators assigned granular admin roles — are affected; the advisory data does not name specific product versions. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply Ping Identity's patch for CVE-2026-20773 as soon as it is available for your deployment, since the advisory does not list fixed versions. In the meantime, audit which administrative roles in your environment can access the expression testing feature and remove that access from accounts that do not require it, enforce least-privilege role assignment in the admin console, and review administrative audit logs for expression-evaluation activity by lower-privileged admins. Restrict administrative console access to trusted networks or VPNs.

Affected
Ping Identity
Estimated exposure
moderatelow thousands of enterprise deployments (order of 1,000–10,000 systems), mostly internal-facing admin consoles — Ping Identity is an enterprise IAM vendor with thousands of PingFederate/PingAccess-class customers, and public internet scans typically show PingFederate-related endpoints on the order of a few thousand hosts, though the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

Weakness
CWE-863
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.