Impact
An improper validation flaw in PingAM set or can enable an attacker to spoof identity information and bypass authentication controls, resulting in privilege escalation or impersonation of legitimate users. The weakness is defined as CWE-290, a failure to properly authenticate or authorize a request.
Affected Systems
Ping Identity’s PingAM OIDC provider is the affected product. All configured instances that expose the OIDC endpoint and have claim validation disabled or improperly configured are vulnerable. No specific version details are listed, so all current deployments should be checked against the vendor advisory.
Risk and Exploitability
The vulnerability carries a CVSS base score of 9.5, indicating critical severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. The likely attack vector is an externally reachable OIDC endpoint that accepts a malicious request; the attacker can set claims carried in the ID Token without being detected. Exploitation would require only the ability to send crafted OIDC requests to the vulnerable server, making this risk high if the endpoint is exposed to untrusted networks.
OpenCVE Enrichment