Junglewise Threat Intelligence

CVE-2025-20628: Ping Identity PingIDM access control vulnerability in Remote Connector Servers

CVE-2025-20628 · Severity: info · CVSS 6.9 · Published 2026-04-07

Executive brief

PingIDM (formerly ForgeRock Identity Management) is an identity management platform used to manage user credentials and access. A security flaw in how the system handles remote connector servers allows attackers to impersonate a trusted server. If successful, an attacker could intercept or change sensitive user data, including passwords and account recovery details, potentially leading to full account takeovers.

Technical details

An insufficient granularity of access control vulnerability (CWE-1220) exists in PingIDM (formerly ForgeRock Identity Management) affecting Remote Connector Servers (RCS). When an RCS is configured to run in client mode, the system fails to provide adequate access control rules, allowing an attacker to spoof a client-mode RCS. This network-based attack requires high access complexity and specific timing/preconditions but requires no privileges or user interaction. A successful exploit allows the attacker to intercept or modify security-relevant identity properties, such as passwords and recovery information. The vulnerability affects multiple versions including 7.5.0 and various sub-versions of 7.1 through 7.4.

Affected products

  • Ping Identity PingIDM 7.5.0, 7.4.0 through 7.4.1, 7.3.0 through 7.3.1, 7.2.0 through 7.2.2, and all versions up to 7.1.x

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory

References