2026-09-14 11:18CVE-2026-21391Ping Identity
PUBLISHED5.2CWE-290

Improper Claim Validation in PingAM OIDC Provider

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

Problem type

Affected products

Ping Identity

PingAM

8.1.0 - AFFECTED

<= 8.0.2 - AFFECTED

<= 7.5.2 - AFFECTED

<= 7.4.2 - AFFECTED

<= 7.3.3 - AFFECTED

<= 7.2.2 - AFFECTED

<= 7.1.4 - AFFECTED

<= 7.0.2 - AFFECTED

< 7.0.0 - AFFECTED

References

GitHub Security Advisories

GHSA-cvq5-qf5h-v345

An improper validation vulnerability exists within PingAM where a well-crafted request allows...

https://github.com/advisories/GHSA-cvq5-qf5h-v345

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-21391
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-21391",
    "assignerOrgId": "5998a2e9-ae88-42cd-b6e0-7564fd979f9e",
    "assignerShortName": "Ping Identity",
    "dateUpdated": "2026-09-14T11:18:33.045Z",
    "dateReserved": "2026-01-07T15:15:23.421Z",
    "datePublished": "2026-09-14T11:18:33.045Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "5998a2e9-ae88-42cd-b6e0-7564fd979f9e",
        "shortName": "Ping Identity",
        "dateUpdated": "2026-09-14T11:18:33.045Z"
      },
      "title": "Improper Claim Validation in PingAM OIDC Provider",
      "descriptions": [
        {
          "lang": "en",
          "value": "An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<div>An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.</div><br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Ping Identity",
          "product": "PingAM",
          "defaultStatus": "affected",
          "versions": [
            {
              "version": "8.1.0",
              "status": "affected",
              "versionType": "semver"
            },
            {
              "version": "8.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "8.0.2"
            },
            {
              "version": "7.5.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.5.2"
            },
            {
              "version": "7.4.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.4.2"
            },
            {
              "version": "7.3.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.3.3"
            },
            {
              "version": "7.2.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.2"
            },
            {
              "version": "7.1.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.4"
            },
            {
              "version": "7.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.2"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "7.0.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-290 Authentication bypass by spoofing",
              "cweId": "CWE-290",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.pingidentity.com/s/article/PingAM-Security-Advisory-202603"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-21",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-21 Exploitation of Trusted Identifiers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
            }
          ]
        }
      ]
    }
  }
}