ZeroHour

CVE-2026-21391

moderate

ID Token Claim Override Enables Authentication Bypass in Ping Identity PingAM

CVSS 4.0
9.5 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-21391 is an improper validation vulnerability (CWE-290, authentication bypass by spoofing) in Ping Identity PingAM that allows an unauthenticated remote attacker to set or override arbitrary or protected ID Token claims via a well-crafted request. In configurations where such claims are trusted to drive authentication or authorization decisions, an attacker can spoof identity and bypass authentication controls, resulting in privilege escalation or user impersonation. Exploitation requires no privileges or user interaction and has low attack complexity, but the vulnerable behavior depends on specific deployment configurations (attack prerequisites present). The flaw is rated critical with a CVSS 4.0 score of 9.5. No public proof-of-concept exists and the issue is not on the CISA KEV list, so exploitation in the wild is not currently known.

What to do: Apply the vendor's patched release as specified in the Ping Identity security advisory for CVE-2026-21391. Review any configuration where ID Token claims influence authentication or authorization outcomes (e.g., OIDC claims handling or custom claim-mapping configurations) and restrict or validate which claims can be supplied by an incoming request. Audit logs for anomalous ID Tokens containing unexpected claim overrides, unexpected successful authentications, or privilege changes that could indicate attempted exploitation.

Affected
Ping Identity PingAM
Estimated exposure
moderateLow thousands of PingAM instances worldwide, plausibly millions of downstream end users behind them — PingAM (formerly ForgeRock AM) is an enterprise IAM product deployed by Ping Identity's base of a few thousand large organizations, typically with multiple instances each; no public install counts or internet-exposure scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

Weakness
CWE-290
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.