CVE-2026-20773
moderate1Role-Based Access Control Flaw in Ping Identity Admin Expression Evaluation
CVE-2026-20773 is a role-based access control flaw (CWE-863) in the administrative expression evaluation functionality of a Ping Identity product, disclosed via Ping Identity's responsible disclosure program. A user holding one of certain administrative roles can trigger the issue by invoking the expression testing capability through the administrative interface, which should only be accessible to higher-privileged administrators. Successful abuse lets the attacker test and evaluate expressions beyond their intended permissions, and the high CVSS 4.0 score (8.5) with high subsequent-system, integrity, and availability impacts indicates the capability could be leveraged to affect downstream systems and data. Organizations running the affected Ping Identity deployment — particularly those with multiple administrators assigned granular admin roles — are affected; the advisory data does not name specific product versions. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply Ping Identity's patch for CVE-2026-20773 as soon as it is available for your deployment, since the advisory does not list fixed versions. In the meantime, audit which administrative roles in your environment can access the expression testing feature and remove that access from accounts that do not require it, enforce least-privilege role assignment in the admin console, and review administrative audit logs for expression-evaluation activity by lower-privileged admins. Restrict administrative console access to trusted networks or VPNs.
| Ping Identity | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.