Description
A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
Published: 2026-09-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized administrative access to expression evaluation
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a role‑based access control flaw in PingFederate’s administrative expression evaluation endpoint. It permits users with certain administrative roles to invoke the expression evaluation feature beyond the permissions that are intended for those roles.

Affected Systems

Ping Identity PingFederate deployments that utilize the administrative expression evaluation endpoint. No specific product version is listed, so any installation that provides this functionality may be affected.

Risk and Exploitability

The CVSS score of 8.5 classifies the flaw as high severity. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. It is not listed in the CISA KEV catalog. The most likely attack vector involves an internal user who possesses an administrative role that should not have access to the expression evaluation endpoint.

Generated by OpenCVE AI on September 15, 2026 at 15:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify if a patch or update from Ping Identity addresses the access control issue in the administrative expression evaluation endpoint.
  • Review role assignments and restrict expression evaluation privileges only to users who truly need them, removing or adjusting roles that grant unintended access.
  • Implement strict separation of roles so that no single role combines unrelated administrative capabilities; audit role configurations regularly.
  • Monitor logs for usage of the expression evaluation endpoint by users who should not have permission to access it.

Generated by OpenCVE AI on September 15, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Ping Identity
Ping Identity pingfederate
Vendors & Products Ping Identity
Ping Identity pingfederate

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.
Title Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Ping Identity Pingfederate
cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2026-09-14T11:19:44.686Z

Reserved: 2026-01-07T15:15:23.409Z

Link: CVE-2026-20773

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:28.996Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:03.820

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-20773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses