Junglewise Threat Intelligence

CVE-2026-21391: Ping Identity PingAM improper validation in ID Token claims

CVE-2026-21391 · Severity: info · Published 2026-09-14

Executive brief

PingAM is an identity and access management (IAM) system used to authenticate users and control access to applications and resources. A validation flaw allows attackers to craft malicious requests that set or override ID Token claims, potentially bypassing authentication and gaining unauthorized access to user accounts or escalating privileges in vulnerable configurations.

Technical details

The vulnerability is an improper validation issue in PingAM's ID Token claim handling. A well-crafted request can be used to set or override arbitrary or protected claims within an ID Token, circumventing normal authentication controls. In certain configurations, this enables authentication bypass via spoofing, allowing an attacker to impersonate legitimate users or escalate privileges. The attack is likely achievable over the network without authentication preconditions. Patches from Ping Identity are expected through their security advisory channels.

Affected products

  • Ping Identity PingAM

Timeline

  • 2026-09-14: disclosed

References