Executive brief
PingAM is an identity and access management (IAM) system used to authenticate users and control access to applications and resources. A validation flaw allows attackers to craft malicious requests that set or override ID Token claims, potentially bypassing authentication and gaining unauthorized access to user accounts or escalating privileges in vulnerable configurations.
Technical details
The vulnerability is an improper validation issue in PingAM's ID Token claim handling. A well-crafted request can be used to set or override arbitrary or protected claims within an ID Token, circumventing normal authentication controls. In certain configurations, this enables authentication bypass via spoofing, allowing an attacker to impersonate legitimate users or escalate privileges. The attack is likely achievable over the network without authentication preconditions. Patches from Ping Identity are expected through their security advisory channels.
Affected products
- Ping Identity PingAM
Timeline
- 2026-09-14: disclosed