Description
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
Published: 2026-09-14
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary ID Token claim manipulation leading to authentication bypass
Action: Immediate Patch
AI Analysis

Impact

An improper validation flaw in PingAM set or can enable an attacker to spoof identity information and bypass authentication controls, resulting in privilege escalation or impersonation of legitimate users. The weakness is defined as CWE-290, a failure to properly authenticate or authorize a request.

Affected Systems

Ping Identity’s PingAM OIDC provider is the affected product. All configured instances that expose the OIDC endpoint and have claim validation disabled or improperly configured are vulnerable. No specific version details are listed, so all current deployments should be checked against the vendor advisory.

Risk and Exploitability

The vulnerability carries a CVSS base score of 9.5, indicating critical severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. The likely attack vector is an externally reachable OIDC endpoint that accepts a malicious request; the attacker can set claims carried in the ID Token without being detected. Exploitation would require only the ability to send crafted OIDC requests to the vulnerable server, making this risk high if the endpoint is exposed to untrusted networks.

Generated by OpenCVE AI on September 15, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and deploy the latest PingAM patch or upgrade to a version that fixes the OIDC claim validation flaw.
  • Reconfigure the server to enforce strict claim validation, allowing only whitelisted ID Token claims and rejecting any unexpected or protected claims.
  • Verify that all OIDC clients validate ID token signatures and claim content before accepting authentication and consider adding a manual check to ensure that only trusted claims are processed.

Generated by OpenCVE AI on September 15, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
Title Improper Claim Validation in PingAM OIDC Provider
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2026-09-14T14:25:10.479Z

Reserved: 2026-01-07T15:15:23.421Z

Link: CVE-2026-21391

cve-icon Vulnrichment

Updated: 2026-09-14T14:25:05.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T12:17:38.810

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-21391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing