SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-21391

CRITICAL · CVSS 9.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An improper validation vulnerability in PingAM allows attackers to manipulate ID Token claims through crafted requests, potentially bypassing authentication controls. This could lead to privilege escalation or impersonation of users in certain configurations. Organizations using PingAM should prioritize addressing this critical vulnerability to protect against unauthorized access and potential data breaches.

CVE
CVE-2026-21391
Severity
CRITICAL
CVSS
9.5
EPSS
N/A

Original NVD Description

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.