CVE-2026-21391
moderateID Token Claim Override Enables Authentication Bypass in Ping Identity PingAM
CVE-2026-21391 is an improper validation vulnerability (CWE-290, authentication bypass by spoofing) in Ping Identity PingAM that allows an unauthenticated remote attacker to set or override arbitrary or protected ID Token claims via a well-crafted request. In configurations where such claims are trusted to drive authentication or authorization decisions, an attacker can spoof identity and bypass authentication controls, resulting in privilege escalation or user impersonation. Exploitation requires no privileges or user interaction and has low attack complexity, but the vulnerable behavior depends on specific deployment configurations (attack prerequisites present). The flaw is rated critical with a CVSS 4.0 score of 9.5. No public proof-of-concept exists and the issue is not on the CISA KEV list, so exploitation in the wild is not currently known.
What to do: Apply the vendor's patched release as specified in the Ping Identity security advisory for CVE-2026-21391. Review any configuration where ID Token claims influence authentication or authorization outcomes (e.g., OIDC claims handling or custom claim-mapping configurations) and restrict or validate which claims can be supplied by an incoming request. Audit logs for anomalous ID Tokens containing unexpected claim overrides, unexpected successful authentications, or privilege changes that could indicate attempted exploitation.
| Ping Identity PingAM | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.