Junglewise Threat Intelligence

CVE-2026-20746: Ping Identity PingDirectory memory exhaustion in virtual attribute handling

CVE-2026-20746 · Severity: info · CVSS 6.3 · Published 2026-06-12

Executive brief

Ping Identity PingDirectory is a high-performance directory server used to store and manage identity data. A vulnerability in how the server handles specific internal attributes allows an authorized user to trigger a memory exhaustion condition, potentially leading to a denial-of-service (DoS) state. This occurs when the server is configured to track recent login history and certain virtual attributes are copied.

Technical details

A memory leak vulnerability (CWE-401) exists in Ping Identity PingDirectory's virtual attribute handling mechanism. The issue is triggered when the 'recent login history' feature is enabled and an authorized user performs operations involving the copying of virtual attributes that reference 'ds-privilege-name' values. This can lead to Java heap exhaustion, resulting in a Denial of Service (DoS). The attack requires high privileges (PR:H) and some user interaction (UI:P) according to the vendor's CVSS vector. The issue is addressed in PingDirectory version 11.0.0.1 and later.

Affected products

  • Ping Identity PingDirectory Versions prior to 11.0.0.1

Timeline

  • 2026-03-01: patched: Fixed in version 11.0.0.1 release
  • 2026-06-12: disclosed: Initial advisory publication

References