An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 12:17
Updated : 2026-09-14 15:17
NVD link : CVE-2026-21391
Mitre link : CVE-2026-21391
CVE.ORG link : CVE-2026-21391
JSON object : View
Products Affected
No product.
CWE
CWE-290
Authentication Bypass by Spoofing
