An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
PUBLISHED5.2CWE-290
Improper Claim Validation in PingAM OIDC Provider
Problem type
Affected products
Ping Identity
PingAM
8.1.0 - AFFECTED
<= 8.0.2 - AFFECTED
<= 7.5.2 - AFFECTED
<= 7.4.2 - AFFECTED
<= 7.3.3 - AFFECTED
<= 7.2.2 - AFFECTED
<= 7.1.4 - AFFECTED
<= 7.0.2 - AFFECTED
< 7.0.0 - AFFECTED
References
GitHub Security Advisories
GHSA-cvq5-qf5h-v345
An improper validation vulnerability exists within PingAM where a well-crafted request allows...
https://github.com/advisories/GHSA-cvq5-qf5h-v345An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-21391Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-21391",
"assignerOrgId": "5998a2e9-ae88-42cd-b6e0-7564fd979f9e",
"assignerShortName": "Ping Identity",
"dateUpdated": "2026-09-14T11:18:33.045Z",
"dateReserved": "2026-01-07T15:15:23.421Z",
"datePublished": "2026-09-14T11:18:33.045Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "5998a2e9-ae88-42cd-b6e0-7564fd979f9e",
"shortName": "Ping Identity",
"dateUpdated": "2026-09-14T11:18:33.045Z"
},
"title": "Improper Claim Validation in PingAM OIDC Provider",
"descriptions": [
{
"lang": "en",
"value": "An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<div>An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.</div><br>"
}
]
}
],
"affected": [
{
"vendor": "Ping Identity",
"product": "PingAM",
"defaultStatus": "affected",
"versions": [
{
"version": "8.1.0",
"status": "affected",
"versionType": "semver"
},
{
"version": "8.0.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "8.0.2"
},
{
"version": "7.5.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.5.2"
},
{
"version": "7.4.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.4.2"
},
{
"version": "7.3.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.3.3"
},
{
"version": "7.2.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.2.2"
},
{
"version": "7.1.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.1.4"
},
{
"version": "7.0.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "7.0.2"
},
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "7.0.0"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-290 Authentication bypass by spoofing",
"cweId": "CWE-290",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://support.pingidentity.com/s/article/PingAM-Security-Advisory-202603"
}
],
"impacts": [
{
"capecId": "CAPEC-21",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-21 Exploitation of Trusted Identifiers"
}
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
]
}
]
}
}
}