Description
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.
Published: 2026-08-10
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross-Site Request Forgery weakness in the Administrative Console of PingFederate in versions prior to 13.1. It allows an attacker to cause a logged-in administrator to submit requests that perform privileged actions. The weakness is identified as CWE-352 and is limited to actions that require administrator privileges.

Affected Systems

The affected product is Ping Identity PingFederate. All releases before version 13.1 are vulnerable, regardless of operating system, as reflected by the listed CPE entries for 64‑bit, Linux, and Windows builds.

Risk and Exploitability

The CVSS score of 4.9 indicates a moderate severity. No EPSS data is available, and the vulnerability is not in the CISA KEV catalog. The attack most likely requires a victim administrator to click a malicious link or otherwise submit a forged request while an authenticated session is active. If successful, the attacker can perform any action that the administrator is authorized to perform.

Generated by OpenCVE AI on August 10, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PingFederate to version 13.1 or newer to eliminate the CSRF vulnerability.
  • If an upgrade cannot be performed immediately, limit administrative console access to a trusted network segment and enforce multi‑factor authentication to reduce the likelihood of accidental request submission.
  • Monitor administrative activity logs for unusual or unauthorized actions and maintain least‑privilege access for administrator accounts.

Generated by OpenCVE AI on August 10, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ping_identity:pingfederate:*:*:64_bit:*:*:*:*:*
cpe:2.3:a:ping_identity:pingfederate:*:*:linux:*:*:*:*:*
cpe:2.3:a:ping_identity:pingfederate:*:*:windows:*:*:*:*:*
cpe:2.3:a:ping_identity:pingfederate:*:*:*:*:*:*:*:*

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.
Title PingFederate Administrative Console CSRF weaknesses
First Time appeared Ping Identity
Ping Identity pingfederate
Weaknesses CWE-352
CPEs cpe:2.3:a:ping_identity:pingfederate:*:*:64_bit:*:*:*:*:*
cpe:2.3:a:ping_identity:pingfederate:*:*:linux:*:*:*:*:*
cpe:2.3:a:ping_identity:pingfederate:*:*:windows:*:*:*:*:*
Vendors & Products Ping Identity
Ping Identity pingfederate
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:P'}


Subscriptions

Ping Identity Pingfederate
cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2026-08-28T19:40:37.084Z

Reserved: 2025-04-16T01:21:55.163Z

Link: CVE-2025-32736

cve-icon Vulnrichment

Updated: 2026-08-11T14:24:29.167Z

cve-icon NVD

Status : Received

Published: 2026-08-10T22:17:08.580

Modified: 2026-08-28T22:16:44.920

Link: CVE-2025-32736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T02:15:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)